CVE-2021-47779

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text, potentially enabling privilege escalation.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dolibarr:dolibarr_erp\/crm:14.0.2:*:*:*:*:*:*:*

History

17 Jun 2026, 04:18

Type Values Removed Values Added
Summary
  • (es) Dolibarr ERP-CRM 14.0.2 contiene una vulnerabilidad de cross-site scripting almacenado en el módulo de creación de tickets que permite a usuarios con bajos privilegios inyectar scripts maliciosos. Los atacantes pueden elaborar un mensaje de ticket especialmente diseñado con JavaScript incrustado que se activa cuando un administrador copia el texto, lo que podría permitir la escalada de privilegios.

02 Mar 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 5.4

27 Feb 2026, 03:52

Type Values Removed Values Added
First Time Dolibarr
Dolibarr dolibarr Erp\/crm
CPE cpe:2.3:a:dolibarr:dolibarr_erp\/crm:14.0.2:*:*:*:*:*:*:*
References () https://github.com/Dolibarr - () https://github.com/Dolibarr - Product
References () https://www.dolibarr.org/ - () https://www.dolibarr.org/ - Product
References () https://www.exploit-db.com/exploits/50432 - () https://www.exploit-db.com/exploits/50432 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/dolibarr-erp-crm-stored-cross-site-scripting-xss-privilege-escalation - () https://www.vulncheck.com/advisories/dolibarr-erp-crm-stored-cross-site-scripting-xss-privilege-escalation - Third Party Advisory

16 Jan 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-16 00:16

Updated : 2026-06-17 04:18


NVD link : CVE-2021-47779

Mitre link : CVE-2021-47779

CVE.ORG link : CVE-2021-47779


JSON object : View

Products Affected

dolibarr

  • dolibarr_erp\/crm
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')