CVE-2024-34051: Dolibarr
Medium severity, CVSS 4.6. EPSS: 12% chance of exploitation in the next 30 days.
A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.
Affected products
- Dolibarr Dolibarr: before 19.0.2 (fixed in 19.0.2)
Published 2024-06-03. Last modified 2026-06-17.