CVE-2021-47779: Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text, potentially enabling privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47779?
CVE-2021-47779 is considered a medium severity vulnerability due to its potential for privilege escalation through stored cross-site scripting.
How do I fix CVE-2021-47779?
To fix CVE-2021-47779, upgrade to the latest version of Dolibarr ERP-CRM, which addresses this vulnerability.
Who is affected by CVE-2021-47779?
CVE-2021-47779 affects users of Dolibarr ERP-CRM version 14.0.2 specifically in the ticket creation module.
What type of vulnerability is CVE-2021-47779?
CVE-2021-47779 is a stored cross-site scripting (XSS) vulnerability that allows low-privilege users to inject malicious scripts.
Can CVE-2021-47779 lead to further attacks?
Yes, CVE-2021-47779 can allow attackers to escalate their privileges and potentially compromise the entire system due to the injection of malicious scripts.