Vulnerability Description
Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://www.dolibarr.org/
- https://www.exploit-db.com/exploits/48504
- https://www.vulncheck.com/advisories/dolibarr-ldapphp-persistent-cross-site-scri
FAQ
What is CVE-2020-36966?
CVE-2020-36966 is a vulnerability with a CVSS score of 6.4 (MEDIUM). Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can e...
How severe is CVE-2020-36966?
CVE-2020-36966 has been rated MEDIUM with a CVSS base score of 6.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-36966?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.