Reflected Cross-Site Scripting Vulnerability in Dolibarr by Dolibarr
CVE-2026-71503
Key Information:
Badges
What is CVE-2026-71503?
Dolibarr versions prior to 24.0.0 introduce a reflected cross-site scripting (XSS) vulnerability in the extra fields administration template. The issue arises because the 'type' request parameter is displayed on the webpage without proper JavaScript-context encoding and lacks a Content-Security-Policy header, which can be exploited. An unauthenticated attacker could manipulate an authenticated administrator into visiting a specially crafted URL, potentially allowing the attacker to execute arbitrary JavaScript within the session. This vulnerability can lead to severe security risks, including the unauthorized creation of persistent administrator accounts.
Affected Version(s)
dolibarr 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
