Описание
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:10.0.2:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00313
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
ubuntu
больше 6 лет назад
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.
CVSS3: 5.4
debian
больше 6 лет назад
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoi ...
CVSS3: 5.4
github
больше 3 лет назад
Dolibarr Cross-site Scripting via outgoing email setup feature
EPSS
Процентиль: 54%
0.00313
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79