CVE-2018-16808: XSS
Published Mar 7, 2019
·Updated
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<=7.0.0
7.0.1
dolibarr Dolibarr>=3.8.0<=7.0.0
Event History
Mar 7, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:27 AM
Frequently Asked Questions
1
What is CVE-2018-16808?
CVE-2018-16808 is a vulnerability found in Dolibarr through 7.0.0 that allows for Stored XSS attacks.
2
How severe is CVE-2018-16808?
CVE-2018-16808 has a severity level of medium with a CVSS score of 6.1.
3
Which software versions are affected by CVE-2018-16808?
Dolibarr versions from 3.8.0 to 7.0.0 are affected by CVE-2018-16808.
4
What is the CWE classification of CVE-2018-16808?
CVE-2018-16808 is classified as CWE-79, which is a Cross-Site Scripting (XSS) vulnerability.
5
How can I fix CVE-2018-16808?
To fix CVE-2018-16808, it is recommended to update Dolibarr to a version that is not affected by the vulnerability.