PT-2024-20098 · Dolibarr · Dolibarr

Saimanikanta1992

·

Published

2024-01-25

·

Updated

2025-04-03

·

CVE-2024-23817

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Dolibarr version 18.0.4
Description Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. The vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. This behavior can be exploited to perform various attacks like Cross-Site Scripting (XSS). An attacker can inject a new HTML tag into the returned document and comment out some part of the Dolibarr App Home page HTML code.
Recommendations To remediate the issue, validate and sanitize all user-supplied input, especially within HTML attributes, to prevent HTML injection attacks; and implement proper output encoding when rendering user-provided data to ensure it is treated as plain text rather than executable HTML.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-DOLIBARR-2024-23817
CVE-2024-23817
GHSA-7947-48Q7-CP5M

Affected Products

Dolibarr