Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hv2j-6654-x74q

Опубликовано: 03 июн. 2024
Источник: github
Github: Прошло ревью

Описание

Reflected Cross-Site Scripting (XSS) in Dolibarr

A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

< 19.0.2

19.0.2

EPSS

Процентиль: 79%
0.01258
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.6
ubuntu
больше 1 года назад

A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

CVSS3: 4.6
nvd
больше 1 года назад

A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

CVSS3: 4.6
debian
больше 1 года назад

A Reflected Cross-site scripting (XSS) vulnerability located in htdocs ...

EPSS

Процентиль: 79%
0.01258
Низкий

Дефекты

CWE-79