CVE-2021-25955

Stored XSS in “Dolibarr” leads to privilege escalation

Description

In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are executed in a victim’s browser when they open the page containing the vulnerable field. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account takeover of the admin and due to other vulnerability (Improper Access Control on Private notes) a low privileged user can update the private notes which could lead to privilege escalation.

Remediation

Solution:

  • Update to 14.0.0

Category

9.0
CVSS
Severity: Critical
CVSS 3.1 •
CVSS 2.0 •
EPSS 0.41%
Third-Party Advisory github.com Third-Party Advisory whitesourcesoftware.com
Affected: Dolibarr dolibarr
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2021-25955?
CVE-2021-25955 has been scored as a critical severity vulnerability.
How to fix CVE-2021-25955?
To fix CVE-2021-25955: Update to 14.0.0
Is CVE-2021-25955 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2021-25955 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2021-25955?
CVE-2021-25955 affects Dolibarr dolibarr.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.