Lucene search

K
osvGoogleOSV:GHSA-FVXR-767J-F28V
HistoryMay 24, 2022 - 4:57 p.m.

Dolibarr stored Cross-site Scripting vulnerability

2022-05-2416:57:07
Google
osv.dev
4
dolibarr security vulnerability stored cross-site scripting_privilege escalation user group description.

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

24.8%

Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the “Create/modify other users, groups and permissions” privilege can inject script and can also achieve privilege escalation.

AI Score

5.9

Confidence

High

EPSS

0.001

Percentile

24.8%

Related for OSV:GHSA-FVXR-767J-F28V