Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r3r5-fqfm-9wrh

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Dolibarr Stored Cross-site Scripting in expensereport/card.php

An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

Пакеты

Наименование

dolibarr/dolibarr

composer
Затронутые версииВерсия исправления

<= 7.0.0

7.0.1

EPSS

Процентиль: 42%
0.00199
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 7 лет назад

An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

CVSS3: 6.1
nvd
почти 7 лет назад

An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

CVSS3: 6.1
debian
почти 7 лет назад

An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS ...

EPSS

Процентиль: 42%
0.00199
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79