Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-16687

Опубликовано: 27 сент. 2019
Источник: debian

Описание

Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dolibarrremovedpackage

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 6 лет назад

Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

CVSS3: 5.4
nvd
больше 6 лет назад

Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

CVSS3: 5.4
github
больше 3 лет назад

Dolibarr Cross-site Scripting in a User Profile in a Signature section