从该网页截图中可以获取到以下关于漏洞的关键信息: 漏洞基本信息 EDB-ID: 48504 CVE: N/A Author: MEHMET KELEPÇE Type: WEBAPPS Platform: PHP Date: 2020-05-22 Vulnerable App: Dolibarr 11.0.3 漏洞描述 Title: Dolibarr 11.0.3 - Persistent Cross-Site Scripting Author: Mehmet Kelepce / Gais Cyber Security Date: 2020-04-14 Vendor: https://www.dolibarr.org/ Exploit-DB Author ID: 8763 Remotely Exploitable: Yes Dynamic Coding Language: PHP CVSSv3 Base Score: 7.4 (AV:N, AC:L, PR:L, UI:N, S:C, C:L, I:L, A:L) Bug: XSS - Cross Site Scripting CVE: N/A 漏洞发现 Source: Examining the source code 利用示例 PoC: Vulnerable parameters: host, slave, port Payload (base64): Payload (decode): Parameter file: /dolibarr/admin/ldap.php 风险 Risk: Cookie information of the target user is obtained.