CVE-2020-14475: XSS
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).
Other sources
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.4 and below allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).
— GitHub
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-14475?
CVE-2020-14475 is a reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 that allows remote attackers to inject arbitrary web script or HTML into public/notice.php.
How does CVE-2020-14475 impact Dolibarr 11.0.3?
CVE-2020-14475 allows remote attackers to perform cross-site scripting attacks on the affected Dolibarr version.
What is the severity of CVE-2020-14475?
The severity of CVE-2020-14475 is medium with a CVSS score of 6.1.
How can I fix the CVE-2020-14475 vulnerability in Dolibarr 11.0.3?
To fix the CVE-2020-14475 vulnerability, you should update Dolibarr to a version that includes the fix, such as the latest available version.
Where can I find more information about CVE-2020-14475?
You can find more information about CVE-2020-14475 on the official GitHub repository for Dolibarr.