First published: Tue May 22 2018(Updated: )
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr | <7.0.2 | |
composer/dolibarr/dolibarr | <7.0.2 | 7.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-10095 is medium with a severity value of 6.1.
CVE-2018-10095 affects Dolibarr versions before 7.0.2.
The vulnerability in Dolibarr before 7.0.2 is a cross-site scripting (XSS) vulnerability.
Remote attackers can exploit CVE-2018-10095 by injecting arbitrary web script or HTML using the 'foruserlogin' parameter to 'adherents/cartes/carte.php'.
Yes, you can find references related to CVE-2018-10095 in the following links: [Reference 1](http://www.openwall.com/lists/oss-security/2018/05/21/3), [Reference 2](https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog), [Reference 3](https://github.com/Dolibarr/dolibarr/commit/1dc466e1fb687cfe647de4af891720419823ed56).