PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-6446 Dotclear CVE debrief

CVE-2017-6446 is a cross-site scripting issue in Dotclear 2.11.2 that affects admin/blogs.php and admin/users.php through the sortby and order parameters. NVD rates the issue at CVSS 3.0 6.1 (MEDIUM) and maps it to CWE-79.

Vendor
Dotclear
Product
Unknown
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-05
Original CVE updated
2026-05-13
Advisory published
2017-03-05
Advisory updated
2026-05-13

Who should care

Dotclear administrators, maintainers, and teams operating version 2.11.2 or any deployment that exposes the affected admin pages to authenticated users.

Technical summary

The NVD record identifies Dotclear 2.11.2 as vulnerable and classifies the weakness as CWE-79 (XSS). The published CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network reachability, low attack complexity, and user interaction. The supplied references include a vendor patch changeset, which is the strongest remediation signal in the corpus.

Defensive priority

Medium. Patch or upgrade promptly if you run Dotclear 2.11.2, because the affected issue sits in admin-facing request handling and can impact confidentiality and integrity after user interaction.

Recommended defensive actions

  • Apply the Dotclear vendor patch referenced in the changeset link or upgrade to a version that includes the fix.
  • Review server-side handling of the sortby and order parameters in admin/blogs.php and admin/users.php and ensure untrusted input is properly encoded or validated.
  • Limit access to the admin interface to trusted users and networks where feasible.
  • Monitor affected admin endpoints for unusual request patterns or evidence of injected content.
  • If you use compensating controls such as a web application firewall, add coverage for the affected admin routes while you deploy the vendor fix.

Evidence notes

The corpus contains an NVD CVE record for CVE-2017-6446, a SecurityFocus reference, and a Dotclear changeset marked as a patch. NVD states the affected CPE is dotclear 2.11.2 and assigns CWE-79. The supplied material does not include the fixed version number or a detailed vendor advisory text.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-6446 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-6446

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-6446 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6446

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.