PT-2024-20098 · Dolibarr · Dolibarr
Saimanikanta1992
·
Published
2024-01-25
·
Updated
2025-04-03
·
CVE-2024-23817
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dolibarr version 18.0.4
Description
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. The vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. This behavior can be exploited to perform various attacks like Cross-Site Scripting (XSS). An attacker can inject a new HTML tag into the returned document and comment out some part of the Dolibarr App Home page HTML code.
Recommendations
To remediate the issue, validate and sanitize all user-supplied input, especially within HTML attributes, to prevent HTML injection attacks; and implement proper output encoding when rendering user-provided data to ensure it is treated as plain text rather than executable HTML.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dolibarr