First published: Wed Nov 10 2021(Updated: )
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =13.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-33618.
The title of this vulnerability is 'Dolibarr ERP and CRM 13.0.2 allows XSS via object details as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.'
This is a cross-site scripting (XSS) vulnerability.
The severity of this vulnerability is medium with a CVSS score of 6.1.
To fix this vulnerability, update Dolibarr ERP and CRM to version 13.0.3 or later.