Lucene search

K
osvGoogleOSV:GHSA-Q938-82FW-WFCF
HistoryMay 24, 2022 - 5:15 p.m.

Dolibarr stored Cross-site Scripting vulnerability

2022-05-2417:15:34
Google
osv.dev
3
dolibarr
stored xss
admin account

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

24.8%

In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools –> audit page. This may lead to stealing of the admin account.

AI Score

5.7

Confidence

High

EPSS

0.001

Percentile

24.8%

Related for OSV:GHSA-Q938-82FW-WFCF