First published: Mon Aug 31 2020(Updated: )
Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =11.0.4 | |
composer/dolibarr/dolibarr | <=11.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Dolibarr 11.0.4 is CVE-2020-13828.
The severity of CVE-2020-13828 is medium, with a CVSS score of 5.4.
The affected software version for CVE-2020-13828 is Dolibarr 11.0.4.
Remote authenticated attackers can exploit CVE-2020-13828 by injecting arbitrary web script or HTML via certain parameters in ticket/card.php?action=create and adherents/card.php pages.
At the moment, there is no known fix for CVE-2020-13828. It is recommended to monitor the vendor's website for any updates or patches.