First published: Mon Nov 28 2011(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter in a setup action to admin/company.php, or the PATH_INFO to (2) admin/security_other.php, (3) admin/events.php, or (4) admin/user.php.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr ERP & CRM | =3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4329 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
To fix CVE-2011-4329, upgrade to the latest version of Dolibarr that addresses these cross-site scripting vulnerabilities.
CVE-2011-4329 contains multiple cross-site scripting (XSS) vulnerabilities that allow remote attackers to inject arbitrary web scripts.
CVE-2011-4329 affects Dolibarr version 3.1.0.
The affected components in CVE-2011-4329 include admin/company.php, admin/security_other.php, admin/events.php, and admin/user.php.