Vulnerability Description
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dolibarr | Dolibarr Erp\/Crm | 8.0.2 |
Related Weaknesses (CWE)
References
- https://github.com/Dolibarr/dolibarr/commit/0f06e39d23636bd1e4039ac61a743c79725cPatchThird Party Advisory
- https://github.com/Dolibarr/dolibarr/commit/0f06e39d23636bd1e4039ac61a743c79725cPatchThird Party Advisory
FAQ
What is CVE-2018-19992?
CVE-2018-19992 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adhe...
How severe is CVE-2018-19992?
CVE-2018-19992 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19992?
Check the references section above for vendor advisories and patch information. Affected products include: Dolibarr Dolibarr Erp\/Crm.