CVE-2017-17971
29.12.2017, 18:29
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
Vendor | Product | Version |
---|---|---|
dolibarr | dolibarr_erp\/crm | 6.0.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases