Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

Search CVE reports


Toggle filters

31 – 40 of 121 results


CVE-2021-42220

Medium priority
Vulnerable

A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Vulnerable
Show less packages

CVE-2021-33816

Medium priority
Vulnerable

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Vulnerable
Show less packages

CVE-2021-33618

Medium priority
Vulnerable

Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Vulnerable
Show less packages

CVE-2021-25957

Medium priority
Vulnerable

In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the...

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2021-25956

Medium priority
Vulnerable

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads...

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2021-25955

Medium priority
Vulnerable

In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field...

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2021-25954

Medium priority
Vulnerable

In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to...

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-35136

Medium priority
Vulnerable

Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template...

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-14209

Medium priority
Vulnerable

Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to...

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2020-13828

Medium priority
Vulnerable

Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject,...

1 affected packages

dolibarr

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
dolibarr Not in release Not in release Not in release Not in release Vulnerable
Show less packages