CVE-2017-18259: XSS
Published Apr 11, 2018
·Updated
Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.
Affected Software
2 affected components
composer/dolibarr/dolibarr<=7.0.0
dolibarr Dolibarr Erp\/crm<=7.0.0
Event History
Apr 11, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
May 14, 2022
Advisory Published
03:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2017-18259?
CVE-2017-18259 is considered a medium severity vulnerability due to the potential for stored Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2017-18259?
To fix CVE-2017-18259, upgrade Dolibarr ERP/CRM to version 7.0.1 or higher.
3
Which versions are affected by CVE-2017-18259?
CVE-2017-18259 affects all versions of Dolibarr ERP/CRM up to and including 7.0.0.
4
What type of vulnerability is CVE-2017-18259?
CVE-2017-18259 is identified as a stored Cross-Site Scripting (XSS) vulnerability.
5
What happens if CVE-2017-18259 is exploited?
Exploitation of CVE-2017-18259 may allow an attacker to execute arbitrary scripts in the context of the user's session.