Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.
References
Link | Resource |
---|---|
https://github.com/Dolibarr/dolibarr/issues/7962 | Exploit Third Party Advisory |
Configurations
Information
Published : 2019-07-14 20:15
Updated : 2022-11-17 09:21
NVD link : CVE-2019-1010016
Mitre link : CVE-2019-1010016
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
dolibarr
- dolibarr_erp\/crm