CVE-2011-4814: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATHINFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6) user/home.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4814?
CVE-2011-4814 has been classified as a moderate severity vulnerability due to multiple cross-site scripting vulnerabilities.
How do I fix CVE-2011-4814?
To fix CVE-2011-4814, update Dolibarr to a version that is newer than 3.1.0 and ensure proper input validation and output escaping.
Which versions of Dolibarr are affected by CVE-2011-4814?
CVE-2011-4814 affects Dolibarr versions up to and including 3.1.0, as well as earlier versions.
What types of attacks can CVE-2011-4814 facilitate?
CVE-2011-4814 can facilitate cross-site scripting attacks that enable attackers to inject arbitrary scripts or HTML into web pages.
Are there any known exploits for CVE-2011-4814?
Yes, there are known exploits that leverage the cross-site scripting vulnerabilities in CVE-2011-4814 to affect vulnerable installations.