CVE-2016-1912
MEDIUM5.4EPSS 0.22%Dolibarr ERP and CRM contain XSS Vulnerabilities
發布日:2022/5/17修改日:2024/2/16
描述
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.
受影響套件(1)
- Packagist/dolibarr/dolibarrfrom 0, <= 3.8.3
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2016-1912
- WEBhttp://packetstormsecurity.com/files/135201/Dolibarr-3.8.3-Cross-Site-Scripting.html
- WEBhttps://github.com/Dolibarr/dolibarr/issues/4341
- WEBhttps://github.com/GPCsolutions/dolibarr/commit/0d3181324c816bdf664ca5e1548dfe8eb05c54f8
- WEBhttps://twitter.com/MickaelDorigny/status/684456187870457857
- WEBhttp://www.information-security.fr/xss-dolibarr-version-3-8-3