CVE-2021-33618: XSS
Published Nov 10, 2021
·Updated
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
Affected Software
1 affected component
dolibarr Dolibarr Erp\/crm=13.0.2
Event History
Nov 10, 2021
CVE Published
via MITRE·10:40 PM
Data Sourced
via MITRE·10:40 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this Dolibarr ERP and CRM vulnerability?
The vulnerability ID is CVE-2021-33618.
2
What is the title of this Dolibarr ERP and CRM vulnerability?
The title of this vulnerability is 'Dolibarr ERP and CRM 13.0.2 allows XSS via object details as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.'
3
What type of vulnerability is this Dolibarr ERP and CRM vulnerability?
This is a cross-site scripting (XSS) vulnerability.
4
What is the severity of this Dolibarr ERP and CRM vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.1.
5
How can I fix this Dolibarr ERP and CRM vulnerability?
To fix this vulnerability, update Dolibarr ERP and CRM to version 13.0.3 or later.