CVE-2017-14241: XSS
Published Sep 11, 2017
·Updated
Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.
Affected Software
3 affected componentsFixes available
composer/dolibarr/dolibarr<=6.0
composer/dolibarr/dolibarr<6.0.1
6.0.1
dolibarr Dolibarr=6.0.0
Event History
Sep 11, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
May 17, 2022
Advisory Published
01:05 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-14241?
CVE-2017-14241 is categorized as a low-severity cross-site scripting (XSS) vulnerability.
2
How does CVE-2017-14241 affect Dolibarr ERP/CRM?
CVE-2017-14241 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter.
3
What version of Dolibarr is affected by CVE-2017-14241?
CVE-2017-14241 specifically affects Dolibarr ERP/CRM version 6.0.0.
4
How do I fix CVE-2017-14241?
To mitigate CVE-2017-14241, it is recommended to upgrade to a version of Dolibarr that has patched this vulnerability.
5
Who is impacted by CVE-2017-14241?
Only remote authenticated users of Dolibarr ERP/CRM version 6.0.0 are impacted by CVE-2017-14241.