Vulnerabilities
Vulnerable Software
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
CVSS Score
7.5
EPSS Score
0.511
Published
2023-11-01
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
CVSS Score
5.4
EPSS Score
0.002
Published
2023-10-01


Contact Us

Shodan ® - All rights reserved