PatchSiren cyber security CVE debrief
CVE-2017-6446 Dotclear CVE debrief
CVE-2017-6446 is a cross-site scripting issue in Dotclear 2.11.2 that affects admin/blogs.php and admin/users.php through the sortby and order parameters. NVD rates the issue at CVSS 3.0 6.1 (MEDIUM) and maps it to CWE-79.
- Vendor
- Dotclear
- Product
- Unknown
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-05
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-05
- Advisory updated
- 2026-05-13
Who should care
Dotclear administrators, maintainers, and teams operating version 2.11.2 or any deployment that exposes the affected admin pages to authenticated users.
Technical summary
The NVD record identifies Dotclear 2.11.2 as vulnerable and classifies the weakness as CWE-79 (XSS). The published CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network reachability, low attack complexity, and user interaction. The supplied references include a vendor patch changeset, which is the strongest remediation signal in the corpus.
Defensive priority
Medium. Patch or upgrade promptly if you run Dotclear 2.11.2, because the affected issue sits in admin-facing request handling and can impact confidentiality and integrity after user interaction.
Recommended defensive actions
- Apply the Dotclear vendor patch referenced in the changeset link or upgrade to a version that includes the fix.
- Review server-side handling of the sortby and order parameters in admin/blogs.php and admin/users.php and ensure untrusted input is properly encoded or validated.
- Limit access to the admin interface to trusted users and networks where feasible.
- Monitor affected admin endpoints for unusual request patterns or evidence of injected content.
- If you use compensating controls such as a web application firewall, add coverage for the affected admin routes while you deploy the vendor fix.
Evidence notes
The corpus contains an NVD CVE record for CVE-2017-6446, a SecurityFocus reference, and a Dotclear changeset marked as a patch. NVD states the affected CPE is dotclear 2.11.2 and assigns CWE-79. The supplied material does not include the fixed version number or a detailed vendor advisory text.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-6446 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-6446
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-6446 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6446
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://dev.dotclear.org/2.0/changeset/1e44804e7c85b45f42245111c8c0de100a2ff6e3
[email protected] - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.