First published: Wed Dec 26 2018(Updated: )
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <=8.0.3 | |
Dolibarr Dolibarr | <=8.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dolibarr ERP/CRM vulnerability is CVE-2018-19799.
The severity level of CVE-2018-19799 is medium with a CVSS score of 6.1.
The affected software for CVE-2018-19799 is Dolibarr ERP/CRM version 8.0.3.
The vulnerability CVE-2018-19799 is a cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM through 8.0.3, specifically in the `/exports/export.php?datatoexport=` endpoint.
Yes, there are references available for CVE-2018-19799. You can find them at the following links: [link1](https://nvd.nist.gov/vuln/detail/CVE-2018-19799), [link2](https://pentest.com.tr/exploits/Dolibarr-ERP-CRM-8-0-3-Cross-Site-Scripting.html), [link3](https://www.exploit-db.com/exploits/45945/).