PT-2020-20431 · Dolibarr · Dolibarr

Code16

·

Published

2020-02-16

·

Updated

2025-04-03

·

CVE-2020-9016

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dolibarr version 11.0
Description The issue allows for XSS attacks through the joinfiles, topic, or code parameter, or the HTTP Referer header.
Recommendations For Dolibarr version 11.0, consider restricting access to the vulnerable parameters joinfiles, topic, and code to minimize the risk of exploitation. Additionally, restrict the use of the HTTP Referer header until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2020-9016
CVE-2020-9016
GHSA-JH69-6VV2-WFP5

Affected Products

Dolibarr