CVE-2020-11823: XSS
Published Apr 16, 2020
·Updated
In Dolibarr 10.0.6, if USERLOGINFAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
Affected Software
2 affected components
composer/dolibarr/dolibarr=10.0.6
dolibarr Dolibarr Erp\/crm=10.0.6
Event History
Apr 16, 2020
CVE Published
via MITRE·06:36 PM
Data Sourced
via MITRE·06:36 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:15 PM
Frequently Asked Questions
1
What is the vulnerability ID for this Dolibarr vulnerability?
The vulnerability ID for this Dolibarr vulnerability is CVE-2020-11823.
2
What is the severity level of CVE-2020-11823?
The severity level of CVE-2020-11823 is medium, with a CVSS score of 5.4.
3
How does the stored XSS vulnerability in Dolibarr 10.0.6 occur?
The stored XSS vulnerability occurs when the USER_LOGIN_FAILED feature is active on the admin tools -> audit page in Dolibarr 10.0.6.
4
What is the potential impact of the stored XSS vulnerability in Dolibarr 10.0.6?
The stored XSS vulnerability in Dolibarr 10.0.6 may lead to the stealing of the admin account.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: https://fatihhcelik.blogspot.com/2020/04/dolibarr-stored-xss.html