{"id":"BIT-dolibarr-2020-13828","details":"Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.","aliases":["CVE-2020-13828","GHSA-8r2w-phx4-mgpv"],"modified":"2025-04-03T15:27:09.695913Z","published":"2025-04-03T14:04:27.396Z","database_specific":{"cpes":["cpe:2.3:a:dolibarr:dolibarr_erp/crm:*:*:*:*:*:*:*:*"],"severity":"Medium"},"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13828"},{"type":"WEB","url":"https://www.wizlynxgroup.com/security-research-advisories/vuln/WLX-2020-002"}],"affected":[{"package":{"name":"dolibarr","ecosystem":"Bitnami","purl":"pkg:bitnami/dolibarr"},"ranges":[{"type":"SEMVER","events":[{"introduced":"11.0.4"},{"last_affected":"11.0.4"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/dolibarr/BIT-dolibarr-2020-13828.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}],"schema_version":"1.7.3"}