CVE-2021-33618: Dolibarr ERP and CRM contain XSS Vulnerability
6.1
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.84676%
CWE
Published
5/24/2022
Updated
7/11/2023
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| dolibarr/dolibarr | composer | <= 13.0.2 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The PoC demonstrates XSS via the group management endpoint (/user/group/card.php) through the 'nom' parameter. The vulnerability stems from:
- Direct reflection of unsanitized user input containing < and > characters
- Injection into HTML body context through improper output encoding
- The advisory specifically calls out object detail views as the injection vector
- The file path is explicitly shown in HTTP requests and vulnerability reproduction steps While exact function names aren't provided in public disclosures, the card.php handler's group update logic is the clear entry point based on the PoC and advisory details.