Vulnerabilities > Dolibarr > Dolibarr ERP CRM > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-02-09 CVE-2017-1000509 Cross-site Scripting vulnerability in Dolibarr Erp/Crm 6.0.2
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.
network
low complexity
dolibarr CWE-79
5.4
2017-12-29 CVE-2017-17971 Cross-site Scripting vulnerability in Dolibarr Erp/Crm 6.0.4
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
network
low complexity
dolibarr CWE-79
6.1
2017-05-10 CVE-2017-8879 Improper Authentication vulnerability in Dolibarr Erp/Crm 4.0.4
Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.
low complexity
dolibarr CWE-287
6.8
2017-05-10 CVE-2017-7887 Cross-site Scripting vulnerability in Dolibarr Erp/Crm 4.0.4
Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.
network
low complexity
dolibarr CWE-79
6.1