Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5329
HistoryOct 25, 2017 - 5:29 a.m.

Cross-site Scripting (XSS)

2017-10-2505:29:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

EPSS

0.001

Percentile

23.8%

Dolibarr is vulnerable to cross-site scripting (XSS) attacks. The QUERY_STRING parameter is not escaped for pages being called with ajax. This allows attackers to inject and execute arbitrary webscript.

EPSS

0.001

Percentile

23.8%