CVE-2024-23817: Dolibarr Application Home Page HTML injection vulnerability

Published Jan 25, 2024
·
Updated

Summary Observed a HTML Injection vulnerbaility in the Home page of Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. Specifically, I was able to successfully inject a new HTML tag into the returned document and, as a result, was able to comment out some part of the Dolibarr App Home page HTML code. This behavior can be exploited to perform various attacks like Cross-Site Scripting (XSS).

Details 1. Navigate to the login page of Dolibarr application. 2. Submit a login request with the following payload in an arbitrarily supplied body parameter: "u70ea%22%3e%3c!--HTMLInjectionBySai"=1

HTTP Post Request: POST /dolibarr/index.php?mainmenu=home HTTP/1.1 Host: 192.168.37.129 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,/;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Referer: http://192.168.37.129/dolibarr/index.php Content-Type: application/x-www-form-urlencoded Content-Length: 375 Origin: http://192.168.37.129 Connection: close Cookie: <Redacted> Upgrade-Insecure-Requests: 1

token=697c1f303ef1976a713eda01d20d8eab&actionlogin=login&loginfunction=loginfunction&backtopage=&tz=5.5&tzstring=Asia%2FKolkata&dstobserved=0&dstfirst=&dstsecond=&screenwidth=1280&screenheight=587&dolhidetopmenu=&dolhideleftmenu=&doloptimizesmallscreen=&dolnomousehover=&dolusejmobile=&username=admin&password=manikanta&u70ea%22%3e%3c!--HTMLInjectionBySai=1

3. Upon successful injection of the payload, some part of Home page HTML code was commented out.

POC Kindly go through the below video for detailed steps:

https://user-images.githubusercontent.com/26869643/294010332-ff88d80b-cb26-4870-82d3-fb49f7ecc32f.mp4

Remediation Suggestion Kindly validate and sanitize all user-supplied input, especially within HTML attributes, to prevent HTML injection attacks. Implement proper output encoding when rendering user-provided data to ensure it is treated as plain text rather than executable HTML.

Other sources

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. Specifically, I was able to successfully inject a new HTML tag into the returned document and, as a result, was able to comment out some part of the Dolibarr App Home page HTML code. This behavior can be exploited to perform various attacks like Cross-Site Scripting (XSS). To remediate the issue, validate and sanitize all user-supplied input, especially within HTML attributes, to prevent HTML injection attacks; and implement proper output encoding when rendering user-provided data to ensure it is treated as plain text rather than executable HTML.

MITRE

Affected Software

3 affected components
composer/dolibarr/dolibarr=18.0.4
dolibarr Dolibarr Erp\/crm=18.0.4
dolibarr Dolibarr=18.0.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Dolibarr to a version that resolves this vulnerability.

    Fixed in 18.0.4
  2. Configuration

    Implement proper output encoding when rendering user-provided data on the Dolibarr Home page so injected input (e.g., in HTML attributes) is treated as plain text, not executable HTML.

    Dolibarr application (HTML rendering for Home page) output encoding for user-provided data = Ensure user-supplied data is rendered as plain text (proper output encoding) rather than executable HTML
  3. Configuration

    Validate and sanitize all user-supplied input—particularly values that may be rendered inside HTML attributes—to prevent HTML injection/XSS.

    Dolibarr application (input handling) input validation/sanitization = Validate and sanitize all user-supplied input, especially within HTML attributes

Event History

Jan 25, 2024
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Apr 18, 2024
Advisory Published
via GitHub·04:42 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-23817?

CVE-2024-23817 has been classified as a moderate-severity vulnerability due to the potential for HTML injection.

2

How do I fix CVE-2024-23817?

To fix CVE-2024-23817, upgrade to a patched version of Dolibarr beyond 18.0.4 that addresses HTML injection issues.

3

What systems are affected by CVE-2024-23817?

CVE-2024-23817 specifically affects Dolibarr version 18.0.4.

4

What can an attacker do with CVE-2024-23817?

With CVE-2024-23817, an attacker can inject arbitrary HTML tags into the Dolibarr application, potentially manipulating its rendered content.

5

Is there a workaround for CVE-2024-23817?

Currently, the most effective workaround for CVE-2024-23817 is to upgrade to a secured version of Dolibarr that does not contain the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2024-23817 - Dolibarr Application Home Page HTML injection vulnerability - SecAlerts