CVE-2020-36966
MEDIUMDolibarr 11.0.3 - Stored Cross-Site Scripting via LDAP Synchronization Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-36966. PoCs published by Mehmet Kelepçe.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Dolibarr 11.0.3 via the LDAP synchronization settings page. The payload is injected into the 'host' parameter and executes a JavaScript alert when rendered.
Description
Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Dolibarr 11.0.3 via the LDAP synchronization settings page. The payload is injected into the 'host' parameter and executes a JavaScript alert when rendered.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N