CVE-2015-8685 Information
Description
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the \import external calendar\ page.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
http://packetstormsecurity.com/files/135256/dolibarr-HTML-Injection.html
http://seclists.org/fulldisclosure/2016/Jan/40
https://github.com/Dolibarr/dolibarr/issues/4291
https://github.com/GPCsolutions/dolibarr/commit/0d3181324c816bdf664ca5e1548dfe8eb05c54f8
Multiple
cross-site
scripting
(XSS)
vulnerabilities
in
Dolibarr
ERP/CRM
3.8.3
and
earlier
allow
remote
attackers
to
inject
arbitrary
web
script
or
HTML
via
the
(1)
external
calendar
url
or
(2)
the
bank
name
field
in
the
\import
external
calendar
page.
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: