PT-2017-13317 · Dolibarr · Dolibarr Erp/Crm

Published

2017-09-11

·

Updated

2022-05-17

·

CVE-2017-14241

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dolibarr ERP/CRM version 6.0.0
Description A cross-site scripting (XSS) issue allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to the "/htdocs/admin/menus/edit.php" API endpoint.
Recommendations For Dolibarr ERP/CRM version 6.0.0, as a temporary workaround, consider restricting access to the "/htdocs/admin/menus/edit.php" endpoint until a patch is available. Avoid using the Title parameter in the affected endpoint until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14241
GHSA-H3VG-4X76-V28W

Affected Products

Dolibarr Erp/Crm