First published: Mon Jun 13 2022(Updated: )
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | <16.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2060 is a vulnerability that allows for cross-site scripting (XSS) attacks that are stored in the GitHub repository dolibarr/dolibarr prior to version 16.0 of Dolibarr ERP/CRM.
CVE-2022-2060 affects Dolibarr ERP/CRM versions prior to 16.0, allowing for stored cross-site scripting (XSS) attacks.
CVE-2022-2060 has a severity rating of high, with a CVSS score of 5.4.
To fix CVE-2022-2060, you should update Dolibarr ERP/CRM to version 16.0 or later, as the vulnerability has been addressed in this release.
You can find more information about CVE-2022-2060 in the references provided: [GitHub Commit](https://github.com/dolibarr/dolibarr/commit/2b5b9957c3010a5db9d1988c2efe5b209b16b47f), [Huntr Bounty](https://huntr.dev/bounties/2acfc8fe-247c-4f88-aeaa-042b6b8690a0).