Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-9838 - Vulnerability Database

Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2017-9838

Medium
Reference: CVE-2017-9838
Title: Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter) core/ajax/box.php (PATH_INFO) product/stats/card.php (type parameter) holiday/list.php (month_create month_start and month_end parameters) and don/card.php (societe lastname firstname address zipcode town and email parameters).