Vulnerabilities
Vulnerable Software
Dolibarr:  >> Dolibarr  >> 3.6.1  Security Vulnerabilities
Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).
CVSS Score
9.8
EPSS Score
0.003
Published
2017-06-05
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.
CVSS Score
5.4
EPSS Score
0.002
Published
2016-01-15
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.
CVSS Score
6.1
EPSS Score
0.003
Published
2016-01-15


Contact Us

Shodan ® - All rights reserved