CVE-2015-3935: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (searchnom) field to (1) htdocs/societe/societe.php or (2) htdocs/societe/admin/societe.php.
Other sources
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (searchnom) field to (1) htdocs/societe/societe.php or (2) htdocs/societe/admin/societe.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3935?
The severity of CVE-2015-3935 is classified as medium due to the potential for cross-site scripting attacks.
How do I fix CVE-2015-3935?
To fix CVE-2015-3935, upgrade Dolibarr to version 3.6.1 or later, which includes patches for the vulnerabilities.
What versions of Dolibarr are affected by CVE-2015-3935?
CVE-2015-3935 affects Dolibarr versions 3.5.0 and 3.6.0.
Can CVE-2015-3935 be exploited remotely?
Yes, CVE-2015-3935 can be exploited remotely by attackers injecting scripts through vulnerable fields.
What types of attacks are associated with CVE-2015-3935?
CVE-2015-3935 is associated with cross-site scripting (XSS) attacks, allowing the execution of arbitrary web scripts or HTML.