First published: Wed Apr 11 2018(Updated: )
Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <=7.0.0 | |
Dolibarr ERP & CRM | <=7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18259 is considered a medium severity vulnerability due to the potential for stored Cross-Site Scripting (XSS) attacks.
To fix CVE-2017-18259, upgrade Dolibarr ERP/CRM to version 7.0.1 or higher.
CVE-2017-18259 affects all versions of Dolibarr ERP/CRM up to and including 7.0.0.
CVE-2017-18259 is identified as a stored Cross-Site Scripting (XSS) vulnerability.
Exploitation of CVE-2017-18259 may allow an attacker to execute arbitrary scripts in the context of the user's session.