CVE-2021-42220: XSS
Published Dec 15, 2021
·Updated
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<14.0.3
14.0.3
dolibarr Dolibarr<14.0.3
Event History
Dec 15, 2021
CVE Published
via MITRE·06:32 AM
Data Sourced
via MITRE·06:32 AM
Description
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Dec 16, 2021
Advisory Published
via GitHub·12:02 AM
Frequently Asked Questions
1
What is the vulnerability ID for this cross-site scripting (XSS) vulnerability?
The vulnerability ID for this cross-site scripting (XSS) vulnerability is CVE-2021-42220.
2
What is the severity of CVE-2021-42220?
The severity of CVE-2021-42220 is medium with a CVSS score of 5.4.
3
How does the XSS vulnerability in Dolibarr occur?
The XSS vulnerability in Dolibarr occurs via the ticket creation flow, requiring an admin to copy the payload into a box.
4
What version of Dolibarr is affected by this XSS vulnerability?
The XSS vulnerability affects Dolibarr versions up to and excluding 14.0.3.
5
How can I fix the XSS vulnerability in Dolibarr?
To fix the XSS vulnerability in Dolibarr, update to version 14.0.3 or later.