Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-47779

Опубликовано: 16 янв. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.2

Описание

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text, potentially enabling privilege escalation.

РелизСтатусПримечание
devel

DNE

esm-apps/xenial

needs-triage

jammy

DNE

noble

DNE

questing

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 9%
0.00033
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
23 дня назад

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text, potentially enabling privilege escalation.

CVSS3: 7.2
debian
23 дня назад

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnera ...

CVSS3: 7.2
github
23 дня назад

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text, potentially enabling privilege escalation.

EPSS

Процентиль: 9%
0.00033
Низкий

7.2 High

CVSS3