CVE-2015-3935
EPSS 0.31%Dolibarr ERP and CRM contain Cross-site Scripting Vulnerability
發布日:2022/5/17修改日:2023/11/8
描述
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (`search_nom`) field to (1) `htdocs/societe/societe.php` or (2) `htdocs/societe/admin/societe.php`.
受影響套件(1)
- Packagist/dolibarr/dolibarr>= 3.5.0, < 3.5.8
參考連結(8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2015-3935
- WEBhttp://packetstormsecurity.com/files/132108/Dolibarr-3.5-3.6-HTML-Injection.html
- WEBhttp://seclists.org/fulldisclosure/2015/May/126
- WEBhttps://github.com/dolibarr/dolibarr/commit/a7f6bbd316e9b96216e9b2c7a065c9251c9a8907
- WEBhttps://github.com/Dolibarr/dolibarr/issues/2857
- WEBhttps://github.com/Dolibarr/dolibarr/issues/4291
- WEBhttps://github.com/Dolibarr/dolibarr/issues/4341
- WEBhttps://web.archive.org/web/20210122162903/http://www.securityfocus.com/bid/74926