ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-36966

Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.
5.1
CVSS
1.2
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorNetwork
ComplexityLow
RequirementsNone
PrivilegesLow
User InteractionPassive
Threat
Exploit MaturityUnreported
Vulnerable System
ConfidentialityLow
IntegrityLow
AvailabilityNone
Subsequent System
ConfidentialityLow
IntegrityLow
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusUnavailable

Change Log
DateSourceChangesScore
2026-07-21cve.orginitial, patch: Unavailable1.2

Affected Software
VendorProductVersion
DolibarrDolibarr≤ 11.0.3
Published: 2026-01-30