CVE-2015-3935

EPSS 0.31%

Dolibarr ERP and CRM contain Cross-site Scripting Vulnerability

發布日:2022/5/17修改日:2023/11/8

描述

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (`search_nom`) field to (1) `htdocs/societe/societe.php` or (2) `htdocs/societe/admin/societe.php`.

受影響套件(1)

參考連結(8)