First published: Sun Jan 26 2020(Updated: )
htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =10.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-7996.
The severity of CVE-2020-7996 is medium, with a severity value of 6.1.
CVE-2020-7996 affects Dolibarr version 10.0.6.
CVE-2020-7996 allows cross-site scripting (XSS) attacks via the Referer HTTP header.
Yes, you can find more information about the fix for CVE-2020-7996 in the provided references.