{"id":"CVE-2020-14201","aliases":["GHSA-25h3-mw3p-w8r7"],"url":"https://o3.security/vulnerability/CVE-2020-14201","summary":"Dolibarr CRM allows Privilege Escalation","details":"Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which \"disabled\" is changed to \"enabled\" in the HTML source code.","published":"2020-08-21T19:15:12.123Z","modified":"2026-08-07T16:35:55.491312Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Packagist","name":"dolibarr/dolibarr","fixedVersion":"11.0.5"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/Dolibarr/dolibarr/blob/develop/ChangeLog"},{"type":"EVIDENCE","url":"https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2020-011"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T16:35:55.491312Z"}}