Medium severity5.4NVD Advisory· Published Feb 16, 2020· Updated Jun 17, 2026
CVE-2020-9016
CVE-2020-9016
Description
Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | <= 11.0.0 | — |
Affected products
4- Dolibarr/Dolibarrdescription
- osv-coords2 versions
>= 11.0.0, <= 11.0.0+ 1 more
- (no CPE)range: >= 11.0.0, <= 11.0.0
- (no CPE)range: <= 11.0.0
Patches
Vulnerability mechanics
References
4- code610.blogspot.com/2020/02/this-time-i-tried-to-check-one-of.htmlnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jh69-6vv2-wfp5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-9016ghsaADVISORY
- web.archive.org/web/20201203085334/https://therealcoiffeur.github.io/c10001ghsaWEB
News mentions
0No linked articles in our index yet.