vendor:
Dolibarr
by:
Furkan Karaarslan
7.5
CVSS
HIGH
Stored XSS
79
CWE
Product Name: Dolibarr
Affected Version From: 17.0.1
Affected Version To: 17.0.1
Patch Exists: NO
Related CWE:
CPE: dolibarr
Platforms Tested: Windows, Linux
2023
Dolibarr Version 17.0.1 – Stored XSS
This exploit allows an attacker to inject malicious code in the 'note_public' parameter of the Dolibarr application, leading to a stored XSS vulnerability.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize user input and implement proper output encoding.