Dolibarr

Dolibarr Erp/crm

73 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.23%
  • Veröffentlicht 27.09.2019 20:15:10
  • Zuletzt bearbeitet 21.11.2024 04:30:59

Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 27.09.2019 20:15:10
  • Zuletzt bearbeitet 21.11.2024 04:30:58

Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 16.09.2019 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:30:15

In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

Exploit
  • EPSS 0.13%
  • Veröffentlicht 14.08.2019 23:15:10
  • Zuletzt bearbeitet 21.11.2024 04:27:58

An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The prote...

Exploit
  • EPSS 0.79%
  • Veröffentlicht 29.07.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:42

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 29.07.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:42

Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. Th...

Exploit
  • EPSS 1.63%
  • Veröffentlicht 29.07.2019 16:15:11
  • Zuletzt bearbeitet 21.11.2024 04:20:42

Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application performs insufficient checks on the export parameters to mysqldump, which can lead to execution of arbitrary binarie...

Exploit
  • EPSS 0.75%
  • Veröffentlicht 18.07.2019 13:15:11
  • Zuletzt bearbeitet 21.11.2024 04:17:56

Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 15.07.2019 03:15:10
  • Zuletzt bearbeitet 21.11.2024 04:17:55

Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.

  • EPSS 0.34%
  • Veröffentlicht 03.01.2019 19:29:01
  • Zuletzt bearbeitet 21.11.2024 03:58:58

SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter.