Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-11199

Опубликовано: 29 июл. 2019
Источник: ubuntu
Приоритет: medium
CVSS2: 3.5
CVSS3: 5.4

Описание

Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be exploited by low privileged users to target administrators. The viewimage.php page did not perform any contextual output encoding and would display the content within the uploaded file with a user-requested MIME type.

РелизСтатусПримечание
bionic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps-legacy/xenial

needed

esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

DNE

esm-infra/focal

DNE

focal

DNE

groovy

DNE

Показывать по

3.5 Low

CVSS2

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 7 лет назад

Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be exploited by low privileged users to target administrators. The viewimage.php page did not perform any contextual output encoding and would display the content within the uploaded file with a user-requested MIME type.

CVSS3: 5.4
debian
около 7 лет назад

Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded file ...

CVSS3: 5.4
github
около 4 лет назад

Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be exploited by low privileged users to target administrators. The viewimage.php page did not perform any contextual output encoding and would display the content within the uploaded file with a user-requested MIME type.

3.5 Low

CVSS2

5.4 Medium

CVSS3