Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8116
HistoryJan 04, 2019 - 6:11 a.m.

Cross-Site Scripting (XSS)

2019-01-0406:11:03
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9

EPSS

0.001

Percentile

45.3%

dolibarr is vulnerable to cross-site scripting (XSS). A remote attacker is able to inject arbitrary Javascript into a victim’s browser via the transphrase parameter in notice.php due to the application not performing output encoding before displaying on the user’s browser.

EPSS

0.001

Percentile

45.3%