CVE-2017-14239: XSS
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors, (9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14) ProfId4, (15) ProfId5, or (16) ProfId6 parameter to htdocs/admin/company.php.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14239?
CVE-2017-14239 has been categorized with a moderate severity level due to its potential for cross-site scripting attacks.
How do I fix CVE-2017-14239?
To fix CVE-2017-14239, you should update Dolibarr ERP/CRM to version 6.0.1 or later to mitigate the vulnerabilities.
What versions of Dolibarr are affected by CVE-2017-14239?
CVE-2017-14239 affects Dolibarr ERP/CRM version 6.0.0.
Who can exploit CVE-2017-14239?
Remote authenticated users can exploit CVE-2017-14239 to inject arbitrary web scripts or HTML.
What components are vulnerable in CVE-2017-14239?
CVE-2017-14239 affects multiple components such as CompanyName, CompanyAddress, and EMail among others.