CVE-2013-2092: XSS
Published Nov 20, 2019
·Updated
Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.
Affected Software
2 affected components
debian/dolibarr
dolibarr Dolibarr Erp\/crm=3.3.1
Remediation
Event History
Nov 20, 2019
CVE Published
via MITRE·08:09 PM
Data Sourced
via MITRE·08:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2013-2092?
CVE-2013-2092 is a vulnerability in Dolibarr ERP/CRM 3.3.1 that allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.
2
How does CVE-2013-2092 affect Dolibarr ERP/CRM?
CVE-2013-2092 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php of Dolibarr ERP/CRM 3.3.1.
3
What is the severity of CVE-2013-2092?
The severity of CVE-2013-2092 is medium with a CVSS score of 6.1.
4
How can I fix CVE-2013-2092?
To fix CVE-2013-2092, it is recommended to update Dolibarr ERP/CRM to a version that has the vulnerability patched.
5
Where can I find more information about CVE-2013-2092?
You can find more information about CVE-2013-2092 at the following references: [1] [2] [3]