Описание
Dolibarr ERP and CRM contain XSS Vulnerability
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
Пакеты
Наименование
dolibarr/dolibarr
composer
Затронутые версииВерсия исправления
< 10.0.3
10.0.3
Связанные уязвимости
CVSS3: 5.4
ubuntu
почти 6 лет назад
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
CVSS3: 5.4
nvd
почти 6 лет назад
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
CVSS3: 5.4
debian
почти 6 лет назад
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML docume ...