Identifier

CVE-2020-13828

Package Slug

packagist/dolibarr/dolibarr

Vulnerability

Cross-site Scripting

Description

Dolibarr is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.

Affected Versions

Version 11.0.4

Solution

Upgrade to version 11.0.5 or above.

Last Modified

2020-09-09

source