First published: Wed May 10 2017(Updated: )
Dolibarr ERP/CRM 4.0.4 has XSS in `doli/societe/list.php` via the sall parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <=4.0.4 | |
Dolibarr ERP & CRM | =4.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7887 is rated as a low severity vulnerability due to its exploitation requiring user interaction.
To fix CVE-2017-7887, upgrade Dolibarr ERP/CRM to a version later than 4.0.4.
The impact of CVE-2017-7887 allows attackers to execute arbitrary JavaScript in the context of the user’s session through stored XSS.
CVE-2017-7887 affects Dolibarr ERP/CRM version 4.0.4.
CVE-2017-7887 can be exploited remotely, but it requires an attacker to convince a user to click on a malicious link.