CVE-2017-17971: XSS
Published Dec 29, 2017
·Updated
The testsqlandscriptinject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<=6.0.4
6.0.5
dolibarr Dolibarr Erp\/crm=6.0.4
Event History
Dec 29, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
May 14, 2022
Advisory Published
03:50 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-17971?
CVE-2017-17971 is classified as a medium severity vulnerability due to its potential for XSS exploitation.
2
How can CVE-2017-17971 be exploited?
CVE-2017-17971 can be exploited by injecting malicious scripts into event attributes like onclick or onscroll in Dolibarr ERP/CRM.
3
Is CVE-2017-17971 fixed in later versions of Dolibarr?
Yes, CVE-2017-17971 has been addressed in later releases of Dolibarr ERP/CRM beyond version 6.0.4.
4
What is the affected version for CVE-2017-17971?
Version 6.0.4 of Dolibarr ERP/CRM is the specific version affected by CVE-2017-17971.
5
How do I mitigate CVE-2017-17971?
To mitigate CVE-2017-17971, upgrading to a newer version of Dolibarr ERP/CRM that patches the vulnerability is recommended.