Dolibarr

Dolibarr Erp/crm

73 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.72%
  • Published 26.11.2019 15:15:12
  • Last modified 21.11.2024 04:34:19

Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.

  • EPSS 3.81%
  • Published 20.11.2019 21:15:11
  • Last modified 21.11.2024 01:51:01

Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.

  • EPSS 0.77%
  • Published 20.11.2019 21:15:11
  • Last modified 21.11.2024 01:51:01

Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.

  • EPSS 0.73%
  • Published 20.11.2019 20:15:11
  • Last modified 21.11.2024 01:51:00

SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.

Exploit
  • EPSS 0.32%
  • Published 16.10.2019 18:15:25
  • Last modified 21.11.2024 04:32:34

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.

Exploit
  • EPSS 0.32%
  • Published 16.10.2019 18:15:25
  • Last modified 21.11.2024 04:32:34

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.

Exploit
  • EPSS 0.32%
  • Published 16.10.2019 18:15:25
  • Last modified 21.11.2024 04:32:34

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.

  • EPSS 0.47%
  • Published 15.10.2019 12:15:10
  • Last modified 21.11.2024 04:31:53

There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.

Exploit
  • EPSS 0.17%
  • Published 27.09.2019 20:15:10
  • Last modified 21.11.2024 04:30:59

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

Exploit
  • EPSS 0.17%
  • Published 27.09.2019 20:15:10
  • Last modified 21.11.2024 04:30:59

Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.