CVE-2020-13828: XSS
Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Dolibarr 11.0.4?
The vulnerability ID for Dolibarr 11.0.4 is CVE-2020-13828.
What is the severity of CVE-2020-13828?
The severity of CVE-2020-13828 is medium, with a CVSS score of 5.4.
What is the affected software version for CVE-2020-13828?
The affected software version for CVE-2020-13828 is Dolibarr 11.0.4.
How can remote authenticated attackers exploit CVE-2020-13828?
Remote authenticated attackers can exploit CVE-2020-13828 by injecting arbitrary web script or HTML via certain parameters in ticket/card.php?action=create and adherents/card.php pages.
Is there a fix available for CVE-2020-13828?
At the moment, there is no known fix for CVE-2020-13828. It is recommended to monitor the vendor's website for any updates or patches.