Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Erwan Robin

Pesquisador deDIGITEMIS CYBERSECURITY & PRIVACY
#16972de 53,632
15.9CVSS total
Vulnerabilidades · 2
Média
1
Crítica
1
PT-2019-9375
6.1
2019-03-07
Dolibarr · Dolibarr · CVE-2018-16808
**Name of the Vulnerable Software and Affected Versions** Dolibarr versions prior to 7.0.1 **Description** The issue concerns Stored XSS in the expense reports plugin. It occurs via the `comments` parameter, or a public or private note, in the expensereport/card.php file. **Recommendations** For versions prior to 7.0.1, update to version 7.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the expensereport/card.php file or disabling the expense reports plugin until a patch is available. Avoid using the `comments` parameter in the affected plugin until the issue is resolved.
PT-2019-9376
9.8
2019-03-07
Dolibarr · Dolibarr · CVE-2018-16809
**Name of the Vulnerable Software and Affected Versions** Dolibarr versions prior to 7.0.1 **Description** An issue was discovered in the expense reports module, specifically in expensereport/card.php, which allows SQL injection via the integer parameters `qty` and `value unit`. **Recommendations** For versions prior to 7.0.1, update to version 7.0.1 or later to resolve the issue.