Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8081
HistoryDec 27, 2018 - 1:19 a.m.

Cross-Site Scripting (XSS)

2018-12-2701:19:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.002

Percentile

64.7%

dolibarr/dolibarr is vulnerable to cross-site scripting (XSS). The datatoexport parameter in /exports/export.php is not properly sanitized, which would allow a remote attacker to inject arbitrary Javascript into a victim’s browser to steal session tokens or perform unwanted actions on behalf of the user.