CVE-2017-14240: Infoleak
Published Sep 11, 2017
·Updated
There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter.
Affected Software
3 affected componentsFixes available
composer/dolibarr/dolibarr<=6.0.0
composer/dolibarr/dolibarr<=6.0.0
6.0.1
dolibarr Dolibarr=6.0.0
Remediation
Event History
Sep 11, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
May 17, 2022
Advisory Published
01:05 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-14240?
CVE-2017-14240 is rated as a medium severity vulnerability due to its potential for sensitive information disclosure.
2
How do I fix CVE-2017-14240?
To mitigate CVE-2017-14240, upgrade to a version of Dolibarr ERP/CRM that is higher than 6.0.0.
3
What type of information can be disclosed by CVE-2017-14240?
CVE-2017-14240 can result in sensitive information being disclosed through the file parameter in document.php.
4
Which version of Dolibarr is affected by CVE-2017-14240?
CVE-2017-14240 affects Dolibarr ERP/CRM version 6.0.0.
5
Is CVE-2017-14240 a remote or local vulnerability?
CVE-2017-14240 is considered a remote vulnerability as it can be exploited over the network.