Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1912

Опубликовано: 15 янв. 2016
Источник: debian

Описание

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dolibarrfixed3.5.8+dfsg1-1package
dolibarrfixed3.5.5+dfsg1-1+deb8u1jessiepackage

Примечания

  • https://github.com/Dolibarr/dolibarr/issues/4341

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.

CVSS3: 5.4
nvd
около 10 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.

CVSS3: 5.4
github
больше 3 лет назад

Dolibarr ERP and CRM contain XSS Vulnerabilities