Описание
Cross-site scripting in Dolibarr
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
Пакеты
Наименование
dolibarr/dolibarr
composer
Затронутые версииВерсия исправления
< 10.0.2
10.0.2
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 6 лет назад
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
CVSS3: 6.1
nvd
больше 6 лет назад
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
CVSS3: 6.1
debian
больше 6 лет назад
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-A ...