PT-2020-19907 · Dolibarr · Dolibarr

Published

2020-01-26

·

Updated

2025-04-03

·

CVE-2020-7996

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dolibarr version 10.0.6
Description The issue allows for XSS via the Referer HTTP header in the htdocs/user/passwordforgotten.php file.
Recommendations For Dolibarr version 10.0.6, consider disabling access to the htdocs/user/passwordforgotten.php file until a patch is available. Restrict the use of the Referer HTTP header to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2020-7996
CVE-2020-7996
GHSA-V384-JQMQ-FC74

Affected Products

Dolibarr