CVE-2015-3935

EPSS 0.31%

Dolibarr ERP and CRM contain Cross-site Scripting Vulnerability

Published: 5/17/2022Modified: 11/8/2023
Also known as:GHSA-6fw8-vf2x-4wpm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (`search_nom`) field to (1) `htdocs/societe/societe.php` or (2) `htdocs/societe/admin/societe.php`.

Affected packages (1)

References (8)