Vulnerability record · CVE-2018-10095 · published 22 May 2018
CVE-2018-10095: Dolibarr reflected XSS via foruserlogin parameter
Dolibarr · Dolibarr
Dolibarr before 7.0.2 reflects the foruserlogin parameter on adherents/cartes/carte.php without proper output encoding, allowing arbitrary script or HTML injection. Because the flaw sits in a member card page, an attacker can craft a link that executes script in the victim's browser session. The record is thin on affected version detail beyond the fixed 7.0.2 release.
Description
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium at 6.1 and it requires user interaction, though the very high EPSS score and broad Dolibarr deployment warrant prompt patching.
What it is
Dolibarr before 7.0.2 reflects the foruserlogin parameter on adherents/cartes/carte.php without proper output encoding, allowing arbitrary script or HTML injection. Because the flaw sits in a member card page, an attacker can craft a link that executes script in the victim's browser session. The record is thin on affected version detail beyond the fixed 7.0.2 release.
Impact
An attacker can run script in the context of a logged-in Dolibarr user, potentially stealing session cookies or performing actions as that user. The CVSS scope change indicates the injected content can affect resources beyond the vulnerable component.
Attack surface
Reached over the network through a crafted URL targeting the foruserlogin parameter; no authentication is required to deliver the payload, but the victim must interact with the link. The CVSS vector confirms UI:R and PR:N.
Exploitation
Not listed in CISA KEV and no ransomware associations are recorded. EPSS is very high at 0.86988 (99.7th percentile), and references include a patch commit and third-party advisory, but no public exploit tag is present.
What to do
- Upgrade Dolibarr to 7.0.2 or later, which contains the patch commit 1dc466e1fb687cfe647de4af891720419823ed56.
- If immediate upgrade is not possible, restrict access to adherents/cartes/carte.php and related member card endpoints.
- Apply output encoding or input validation to the foruserlogin parameter as a temporary compensating control.
- Review web server and application logs for requests containing script-like payloads in foruserlogin.
- Educate users not to click unsolicited links to Dolibarr member card pages.
Detection
- Search HTTP access logs for requests to adherents/cartes/carte.php with foruserlogin values containing angle brackets, script tags or event handlers.
- Monitor for encoded or obfuscated payloads in the foruserlogin query parameter.
- Alert on anomalous referrer or user-agent patterns hitting member card endpoints.
- Correlate suspicious requests with subsequent session anomalies or unexpected account actions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2018/05/21/3 | Mailing List |
| https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog | Issue TrackingVendor Advisory |
| https://github.com/Dolibarr/dolibarr/commit/1dc466e1fb687cfe647de4af891720419823ed56 | Issue TrackingPatchVendor Advisory |
| https://sysdream.com/news/lab/2018-05-21-cve-2018-10095-dolibarr-xss-injection-vulnerability/ | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2018/05/21/3 | Mailing List |
| https://github.com/Dolibarr/dolibarr/blob/7.0.2/ChangeLog | Issue TrackingVendor Advisory |
| https://github.com/Dolibarr/dolibarr/commit/1dc466e1fb687cfe647de4af891720419823ed56 | Issue TrackingPatchVendor Advisory |
| https://sysdream.com/news/lab/2018-05-21-cve-2018-10095-dolibarr-xss-injection-vulnerability/ | Third Party Advisory |
Track CVE-2018-10095 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-10095), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.