Описание
Dolibarr stored Cross-site Scripting vulnerability
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
Пакеты
Наименование
dolibarr/dolibarr
composer
Затронутые версииВерсия исправления
= 10.0.6
Отсутствует
Связанные уязвимости
CVSS3: 5.4
ubuntu
почти 6 лет назад
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
CVSS3: 5.4
nvd
почти 6 лет назад
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
CVSS3: 5.4
debian
почти 6 лет назад
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored ...