CVE-2026-71503 · One link, opened once, mints a second admin
This story is from 2026-08-25. It is preserved in the archive; the latest stories are on the live feed.
CVSS 9.3 · Reflected XSS (CWE-79), chained to admin creation · Fixed in Dolibarr 24.0.0 Think of a contractor's badge that, when scanned at reception, silently prints a second master key, and the guard hands it over, because the request came from inside the building. The attack in six steps A link…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-08-25 09:02 · DEV Community — AI
CVE-2026-71503 · One link, opened once, mints a second admin