Source: dolibarr Version: 5.0.4+dfsg3-1 Severity: important Tags: security upstream Forwarded: https://github.com/Dolibarr/dolibarr/issues/8000
Hi, the following vulnerability was published for dolibarr. CVE-2017-17971[0]: | The test_sql_and_script_inject function in htdocs/main.inc.php in | Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick | nor onscroll, which allows XSS. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2017-17971 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17971 [1] https://github.com/Dolibarr/dolibarr/issues/8000 Please adjust the affected versions in the BTS as needed. Regards, Salvatore