6.1
CVSSv3

CVE-2017-17971

Published: 29/12/2017 Updated: 17/11/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

Vulnerable Product Search on Vulmon Subscribe to Product

dolibarr dolibarr erp\\/crm 6.0.4

Github Repositories

my CVE list

myCVE Attack Vector CVE ID Reference XSS CVE-2017-17971 wwwcvedetailscom/cve/CVE-2017-17971/ CVE-2017-18004 wwwcvedetailscom/cve/CVE-2017-18004/ Execute Code CVE-2018-3814 wwwcvedetailscom/cve/CVE-2018-3814/

myCVE Attack Vector CVE ID Reference XSS CVE-2017-17971 wwwcvedetailscom/cve/CVE-2017-17971/ CVE-2017-18004 wwwcvedetailscom/cve/CVE-2017-18004/ Execute Code CVE-2018-3814 wwwcvedetailscom/cve/CVE-2018-3814/