CVE-2017-17898: Infoleak
Published Dec 24, 2017
·Updated
Dolibarr ERP/CRM version 6.0.4 does not block direct requests to .tpl.php files, which allows remote attackers to obtain sensitive information.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<=6.0.4
6.0.5
dolibarr Dolibarr Erp\/crm=6.0.4
Remediation
Event History
Dec 24, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·03:51 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-17898?
CVE-2017-17898 is considered a medium severity vulnerability due to potential information exposure.
2
How do I fix CVE-2017-17898?
To fix CVE-2017-17898, upgrade Dolibarr ERP/CRM to version 6.0.5 or later.
3
What versions are affected by CVE-2017-17898?
CVE-2017-17898 affects Dolibarr ERP/CRM version 6.0.4.
4
Can CVE-2017-17898 lead to data breaches?
Yes, CVE-2017-17898 can lead to data breaches by allowing remote attackers to access sensitive information.
5
What type of vulnerability is CVE-2017-17898?
CVE-2017-17898 is a direct request vulnerability that exposes template files to unauthorized access.