CVE-2015-3935

medium
Published 2015-06-10 · Modified 2023-11-08
CVSS v3
CVSS v2
4.3
VIR risk
4.3

Description

Dolibarr ERP and CRM contain Cross-site Scripting Vulnerability

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
php Packagistdolibarr/dolibarr>=3.5.0,<3.5.83.5.8

Application impact

VendorProductVersionsFixed
dolibarrdolibarr3.5.0
dolibarrdolibarr3.6.0

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.