Bugzilla – Bug 933195
CVE-2015-3935: dolibarr HTML injection
Last modified: 2015-11-10 00:51:45 UTC
Courtesy bug for Application:ERP:Dolibarr dolibarr HTML injectsion in dolibar.. https://github.com/Dolibarr/dolibarr/issues/2857 https://github.com/GPCsolutions/dolibarr/commit/a7f6bbd316e9b96216e9b2c7a065c9251c9a8907 https://github.com/Dolibarr/dolibarr/pull/2866 https://github.com/Dolibarr/dolibarr/commit/f32215a9fc3abfa69c34d4cf65a044b60ff8e93a References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3935 http://people.canonical.com/~ubuntu-security/cve/2015/CVE-2015-3935.html
bugbot adjusting priority
Bug was related to 3.5 and 3.7 branch. It is already fixed into 3.8 branch.
(In reply to Laurent Destailleur from comment #2) > Bug was related to 3.5 and 3.7 branch. > It is already fixed into 3.8 branch. Thanks for checking. I see that _service:download_src_package:dolibarr-3.6.1.tgz is still present in the package, you may want to remove it if it is no longer required.
_service:download_src_package:dolibarr-3.6.1.tgz was removed.