VDB
CVE-2017-14239
CVE-2017-14239
PUBLISHED
CVSS 5.400000095367432 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors, (9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14) ProfId4, (15) ProfId5, or (16) ProfId6 parameter to htdocs/admin/company.php.
EPSS 0.81% · 54.2th percentile
Risk Scores
CVSS 3.0
5.400000095367432
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.81%
54.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | dolibarr | 0, 3.5.7+dfsg1-1, 3.5.8+dfsg1-1 |
Timeline
- Sep 11, 2017 CVE Published
- Sep 19, 2017 CVE Updated
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Mar 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Jan 10, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-14239 third-party-advisory
- https://github.com/Dolibarr/dolibarr/commit/d26b2a694de30f95e46ea54ea72cc54f0d38e548 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-14239 third-party-advisory