-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| dolibarr/dolibarr | composer | <= 11.0.4 |
The vulnerability manifests in form handlers across multiple modules (ticket, adherents, product, societe) where user-supplied parameters are stored without proper sanitization. Each card.php file contains the endpoint logic that directly processes the mentioned vulnerable parameters (subject, message, address, etc.) through POST requests. The PoC demonstrates these endpoints accept and store raw HTML/script content, indicating missing output encoding when rendering stored values. While exact function names aren't disclosed, the file paths and parameter handling logic described in advisories clearly identify these entry points as vulnerable components.
KEV Misses 88% of Exploited CVEs- Get the report