Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-17971

Опубликовано: 29 дек. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 6.1

Описание

The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

РелизСтатусПримечание
artful

ignored

end of life
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps-legacy/xenial

needed

esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/focal

DNE

Показывать по

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 8 лет назад

The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

CVSS3: 6.1
debian
больше 8 лет назад

The test_sql_and_script_inject function in htdocs/main.inc.php in Doli ...

CVSS3: 6.1
github
больше 4 лет назад

Dolibarr ERP and CRM contain XSS Vulnerability

4.3 Medium

CVSS2

6.1 Medium

CVSS3