PT-2022-14807 · Dolibarr · Dolibarr
Published
2022-06-13
·
Updated
2025-04-03
·
CVE-2022-2060
CVSS v3.1
8.4
High
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
dolibarr/dolibarr versions prior to 16.0
Description
The issue is related to a Cross-site Scripting (XSS) - Stored vulnerability. It affects the admin/accountant.php file, where the fields
town, name, and Accountant code can be used to escape double quote protection.Recommendations
For versions prior to 16.0, update to version 16.0 or later to resolve the issue.
As a temporary workaround, consider restricting input for the
town, name, and Accountant code fields in the admin/accountant.php file to minimize the risk of exploitation.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dolibarr