vendor:
Dolibarr
by:
Mehmet Kelepce / Gais Cyber Security
7.4
CVSS
HIGH
Persistent Cross-Site Scripting
79
CWE
Product Name: Dolibarr
Affected Version From: 11.0.3
Affected Version To: 11.0.3
Patch Exists: NO
Related CWE:
CPE: a:dolibarr:dolibarr:11.0.3
Platforms Tested:
2020
Dolibarr 11.0.3 – Persistent Cross-Site Scripting
The Dolibarr 11.0.3 version is vulnerable to persistent cross-site scripting (XSS) attacks. An attacker can exploit this vulnerability by sending a specially crafted HTTP POST request to the LDAP Synchronization Settings endpoint. The payload is injected into the 'host' parameter, resulting in the execution of arbitrary scripts in the context of the victim's browser.
Mitigation:
To mitigate this vulnerability, it is recommended to apply the vendor-supplied patch or upgrade to a non-vulnerable version.