CVE-2017-14239: Dolibarr
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors, (9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14) ProfId4, (15) ProfId5, or (16) ProfId6 parameter to htdocs/admin/company.php.
Affected products
- Dolibarr Dolibarr: version 6.0.0 only
Published 2017-09-11. Last modified 2026-06-17.