First published: Fri Dec 29 2017(Updated: )
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr Erp\/crm | =6.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17971 is classified as a medium severity vulnerability due to its potential for XSS exploitation.
CVE-2017-17971 can be exploited by injecting malicious scripts into event attributes like onclick or onscroll in Dolibarr ERP/CRM.
Yes, CVE-2017-17971 has been addressed in later releases of Dolibarr ERP/CRM beyond version 6.0.4.
Version 6.0.4 of Dolibarr ERP/CRM is the specific version affected by CVE-2017-17971.
To mitigate CVE-2017-17971, upgrading to a newer version of Dolibarr ERP/CRM that patches the vulnerability is recommended.