Vulnerabilities
Vulnerable Software
Dolibarr:  Security Vulnerabilities
Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.
CVSS Score
6.1
EPSS Score
0.008
Published
2019-11-20
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
CVSS Score
9.8
EPSS Score
0.038
Published
2019-11-20
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
CVSS Score
9.8
EPSS Score
0.007
Published
2019-11-20
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.
CVSS Score
5.4
EPSS Score
0.003
Published
2019-10-16
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.
CVSS Score
5.4
EPSS Score
0.003
Published
2019-10-16
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.
CVSS Score
5.4
EPSS Score
0.003
Published
2019-10-16
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
CVSS Score
6.1
EPSS Score
0.005
Published
2019-10-15
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-09-27
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-09-27
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
CVSS Score
5.4
EPSS Score
0.002
Published
2019-09-27


Contact Us

Shodan ® - All rights reserved