High severity7.2NVD Advisory· Published Dec 23, 2020· Updated Jun 17, 2026
CVE-2020-35136
CVE-2020-35136
Description
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | < 12.0.4 | 12.0.4 |
Affected products
5- Dolibarr/Dolibarrdescription
- osv-coords2 versions
>= 12.0.3, <= 12.0.3+ 1 more
- (no CPE)range: >= 12.0.3, <= 12.0.3
- (no CPE)range: < 12.0.4
Patches
Vulnerability mechanics
References
7- github.com/Dolibarr/dolibarr/commit/4fcd3fe49332baab0e424225ad10b76b47ebcbacnvdPatchThird Party AdvisoryWEB
- bilishim.com/2020/12/18/zero-hunting-2.htmlnvdExploitThird Party AdvisoryWEB
- github.com/Dolibarr/dolibarr/releasesnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-7x8g-h246-gvx3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-35136ghsaADVISORY
- sourceforge.net/projects/dolibarr/nvdProductThird Party Advisory
- sourceforge.net/projects/dolibarrghsaWEB
News mentions
0No linked articles in our index yet.