Reflected cross-site scripting (XSS) In dolibarr/dolibarr
Description
Dolibarr Cross-site Scripting via the qty parameter in product/fournisseurs.php Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 10.0.4 |
Aliases
1. 2. 3. 4.
References
1. 2. 3.