PT-2022-14807 · Dolibarr · Dolibarr

Published

2022-06-13

·

Updated

2025-04-03

·

CVE-2022-2060

CVSS v3.1

8.4

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dolibarr/dolibarr versions prior to 16.0
Description The issue is related to a Cross-site Scripting (XSS) - Stored vulnerability. It affects the admin/accountant.php file, where the fields town, name, and Accountant code can be used to escape double quote protection.
Recommendations For versions prior to 16.0, update to version 16.0 or later to resolve the issue. As a temporary workaround, consider restricting input for the town, name, and Accountant code fields in the admin/accountant.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2022-2060
CVE-2022-2060
GHSA-8FVR-7945-MG7W

Affected Products

Dolibarr