Server side cross-site scripting In dolibarr/dolibarr
Description
Dolibarr ERP and CRM contain XSS Vulnerability Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 6.0.1 |
Aliases
1. 2. 3. 4.
References
1.