Impact
Dolibarr versions prior to 24.0.0 contain a reflected cross‑site scripting flaw in the extra fields administration template. The flaw arises because the type request parameter is echoed directly into an inline script block without proper JavaScript‑context encoding, and no Content‑Security‑Policy header is sent. An attacker who can craft a malicious URL can cause an administrator to load the URL, resulting in arbitrary JavaScript execution within the administrator's session and the creation of a new persistent administrator account.
Affected Systems
The vulnerability affects the Dolibarr application from the Dolibarr vendor, specifically all releases before version 24.0.0. Users running those older versions are at risk unless they upgrade to 24.0.0 or later.
Risk and Exploitability
The CVSS score of 5.1 places this vulnerability in the medium severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires an unauthenticated attacker to entice an authenticated administrator to visit a crafted URL, the exploit path is non‑remote and leverages social engineering. Nevertheless, once the URL is visited, arbitrary JavaScript runs in the administrator's browser context with the credentials and privileges of that user, enabling the attacker to create a new administrator account and gain elevated access to the affected system.
OpenCVE Enrichment