← Vulnerability feed

Vulnerability record · CVE-2018-10095 · published 22 May 2018

CVE-2018-10095: Dolibarr reflected XSS via foruserlogin parameter

Dolibarr · Dolibarr

Dolibarr before 7.0.2 reflects the foruserlogin parameter on adherents/cartes/carte.php without proper output encoding, allowing arbitrary script or HTML injection. Because the flaw sits in a member card page, an attacker can craft a link that executes script in the victim's browser session. The record is thin on affected version detail beyond the fixed 7.0.2 release.

6.1 CVSS 3.0 Medium EPSS 87% · top 0.3% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

medium priorityCVSS rates it medium at 6.1 and it requires user interaction, though the very high EPSS score and broad Dolibarr deployment warrant prompt patching.

What it is

Dolibarr before 7.0.2 reflects the foruserlogin parameter on adherents/cartes/carte.php without proper output encoding, allowing arbitrary script or HTML injection. Because the flaw sits in a member card page, an attacker can craft a link that executes script in the victim's browser session. The record is thin on affected version detail beyond the fixed 7.0.2 release.

Impact

An attacker can run script in the context of a logged-in Dolibarr user, potentially stealing session cookies or performing actions as that user. The CVSS scope change indicates the injected content can affect resources beyond the vulnerable component.

Attack surface

Reached over the network through a crafted URL targeting the foruserlogin parameter; no authentication is required to deliver the payload, but the victim must interact with the link. The CVSS vector confirms UI:R and PR:N.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded. EPSS is very high at 0.86988 (99.7th percentile), and references include a patch commit and third-party advisory, but no public exploit tag is present.

What to do

  • Upgrade Dolibarr to 7.0.2 or later, which contains the patch commit 1dc466e1fb687cfe647de4af891720419823ed56.
  • If immediate upgrade is not possible, restrict access to adherents/cartes/carte.php and related member card endpoints.
  • Apply output encoding or input validation to the foruserlogin parameter as a temporary compensating control.
  • Review web server and application logs for requests containing script-like payloads in foruserlogin.
  • Educate users not to click unsolicited links to Dolibarr member card pages.

Detection

  • Search HTTP access logs for requests to adherents/cartes/carte.php with foruserlogin values containing angle brackets, script tags or event handlers.
  • Monitor for encoded or obfuscated payloads in the foruserlogin query parameter.
  • Alert on anomalous referrer or user-agent patterns hitting member card endpoints.
  • Correlate suspicious requests with subsequent session anomalies or unexpected account actions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-10095 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19212Dolibarr cross-site scripting vulnerabilityDolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).EPSS 3.9%9.8CVE-2018-16809Dolibarr sql injection vulnerabilityAn issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer paramete…EPSS 2.2%9.8CVE-2018-10094Dolibarr SQL injection via unquoted integer parametersDolibarr before 7.0.2 contains a SQL injection flaw reachable through integer parameters that are not wrapped in quotes. A remote attacker can inject…EPSS 71%analysed9.8CVE-2018-9019Dolibarr sql injection vulnerabilitySQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to…EPSS 4.0%9.8CVE-2017-14238Dolibarr sql injection vulnerabilitySQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via t…EPSS 1.3%9.8CVE-2017-14242Dolibarr sql injection vulnerabilitySQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parame…EPSS 1.3%9.8CVE-2017-9435Dolibarr sql injection vulnerabilityDolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).EPSS 1.5%9.0CVE-2021-25955Dolibarr cross-site scripting vulnerabilityIn “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application use…EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2018-10095), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.