Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9h46-g4c9-7976

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Dolibarr stored Cross-site Scripting in an Email Template section

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

= 9.0.5

Отсутствует

EPSS

Процентиль: 39%
0.00173
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 6 лет назад

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

CVSS3: 5.4
nvd
больше 6 лет назад

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

CVSS3: 5.4
debian
больше 6 лет назад

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_te ...

EPSS

Процентиль: 39%
0.00173
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79