Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6) user/home.php.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dolibarr | Dolibarr Erp\/Crm | <= 3.1.0 |
Related Weaknesses (CWE)
References
- http://www.osvdb.org/77339Broken Link
- http://www.securityfocus.com/archive/1/520619/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/50777Broken LinkExploitThird Party Advisory
- https://github.com/Dolibarr/dolibarr/commit/63820ab37537fdff842539425b2bf2881f0dExploitPatch
- https://github.com/Dolibarr/dolibarr/commit/762f98ab4137749d0993612b4e3544a4207eExploitPatch
- https://github.com/Dolibarr/dolibarr/commit/c539155d6ac2f5b6ea75b87a16f298c0090eExploitPatch
- https://github.com/Dolibarr/dolibarr/commit/d08d28c0cda1f762a47cc205d4363de03df1ExploitPatch
- https://www.htbridge.ch/advisory/multiple_vulnerabilities_in_dolibarr.htmlExploit
- http://www.osvdb.org/77339Broken Link
- http://www.securityfocus.com/archive/1/520619/100/0/threadedBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/50777Broken LinkExploitThird Party Advisory
- https://github.com/Dolibarr/dolibarr/commit/63820ab37537fdff842539425b2bf2881f0dExploitPatch
- https://github.com/Dolibarr/dolibarr/commit/762f98ab4137749d0993612b4e3544a4207eExploitPatch
- https://github.com/Dolibarr/dolibarr/commit/c539155d6ac2f5b6ea75b87a16f298c0090eExploitPatch
- https://github.com/Dolibarr/dolibarr/commit/d08d28c0cda1f762a47cc205d4363de03df1ExploitPatch
FAQ
What is CVE-2011-4814?
CVE-2011-4814 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admi...
How severe is CVE-2011-4814?
CVE-2011-4814 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-4814?
Check the references section above for vendor advisories and patch information. Affected products include: Dolibarr Dolibarr Erp\/Crm.