Lucene search

K
osvGoogleOSV:GHSA-3V8X-286H-9PXP
HistoryMay 14, 2022 - 1:42 a.m.

Dolibarr stored cross-site scripting (XSS) vulnerability

2022-05-1401:42:50
Google
osv.dev
8
dolibarr
xss
vulnerability
user/card.php
web script
html
remoteauthenticatedusers
stored

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

23.6%

A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the “address” (POST) or “town” (POST) parameter to user/card.php.

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

23.6%