-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
While exact function names aren't disclosed in available sources, the vulnerability pattern indicates: 1) Lack of input sanitization in email template content handling (user-controlled data stored raw) 2) Absence of output encoding when rendering templates. The mails_templates.php endpoint is explicitly referenced as the attack vector, and the stored XSS nature implies both vulnerable storage and vulnerable rendering occur in this component. The high confidence comes from the vulnerability's technical description matching classic XSS patterns in template editing interfaces.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| dolibarr/dolibarr | composer | = 9.0.5 |
Ongoing coverage of React2Shell