4.3
CVSSv2

CVE-2011-4814

Published: 14/12/2011 Updated: 10/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote malicious users to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6) user/home.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dolibarr dolibarr erp\\/crm 2.9.0

dolibarr dolibarr erp\\/crm 2.8.1

dolibarr dolibarr erp\\/crm

dolibarr dolibarr erp\\/crm 2.6.0

dolibarr dolibarr erp\\/crm 3.0.0

dolibarr dolibarr erp\\/crm 2.7.1

dolibarr dolibarr erp\\/crm 2.6.1

dolibarr dolibarr erp\\/crm 2.5.0

dolibarr dolibarr erp\\/crm 2.7.0

dolibarr dolibarr erp\\/crm 2.8.0

dolibarr dolibarr erp\\/crm 3.0.1

Exploits

source: wwwsecurityfocuscom/bid/50777/info Dolibarr is prone to multiple cross-site scripting and SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in dynamically generated content Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compr ...