Cross Site Scripting Vulnerability in Dolibarr Product by Dolibarr Association
CVE-2022-30875

6.1MEDIUM

Key Information:

Vendor

Dolibarr

Vendor
CVE Published:
8 June 2022

What is CVE-2022-30875?

Dolibarr version 12.0.5 exhibits a security defect that allows attackers to exploit Cross Site Scripting (XSS) vulnerabilities through improperly handled SQL error messages. This flaw enables the execution of malicious scripts within a user's browser when they visit the affected page, potentially compromising user data and session integrity. Organizations using this version should prioritize patching this vulnerability to strengthen their security posture.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.