Vulnerability Description
A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dolibarr | Dolibarr Erp\/Crm | 21.0.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/Dqtdqt/a942bbce9a5fc851dce366902411c768ExploitThird Party Advisory
- https://github.com/Dolibarr/dolibarr/commit/56710ce9b79a97df093f586c90bdaf6cce6aPatch
- https://github.com/Dolibarr/dolibarr/commit/9aa24d9d9aeab36358c725dae3fe20c96310Patch
- https://github.com/Dolibarr/dolibarr/commit/c0250e4c9106b5c889e512a4771f0205d4f9Patch
- https://github.com/Dolibarr/dolibarr/security/policyIssue Tracking
FAQ
What is CVE-2024-55228?
CVE-2024-55228 is a vulnerability with a CVSS score of 9.0 (CRITICAL). A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parame...
How severe is CVE-2024-55228?
CVE-2024-55228 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-55228?
Check the references section above for vendor advisories and patch information. Affected products include: Dolibarr Dolibarr Erp\/Crm.