First published: Thu Mar 07 2019(Updated: )
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr | >=3.8.0<=7.0.0 | |
composer/dolibarr/dolibarr | <=7.0.0 | 7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16808 is a vulnerability found in Dolibarr through 7.0.0 that allows for Stored XSS attacks.
CVE-2018-16808 has a severity level of medium with a CVSS score of 6.1.
Dolibarr versions from 3.8.0 to 7.0.0 are affected by CVE-2018-16808.
CVE-2018-16808 is classified as CWE-79, which is a Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2018-16808, it is recommended to update Dolibarr to a version that is not affected by the vulnerability.