Описание
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:dolibarr:dolibarr_erp\/crm:10.0.6:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00313
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
ubuntu
почти 6 лет назад
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
CVSS3: 5.4
debian
почти 6 лет назад
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored ...
CVSS3: 5.4
github
больше 3 лет назад
Dolibarr stored Cross-site Scripting vulnerability
EPSS
Процентиль: 54%
0.00313
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79