Lucene search

K
osvGoogleOSV:GHSA-74C7-R9M3-HVJ4
HistoryMay 17, 2022 - 12:53 a.m.

Dolibarr cross-site scripting (XSS) vulnerability

2022-05-1700:53:04
Google
osv.dev
4
dolibarr
cross-site scripting
remote authenticated users
company information
arbitrary script injection
html injection
vulnerability

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

28.6%

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors, (9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14) ProfId4, (15) ProfId5, or (16) ProfId6 parameter to htdocs/admin/company.php.

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

28.6%