PatchSiren cyber security CVE debrief
CVE-2017-6446 Dotclear CVE debrief
CVE-2017-6446 is a cross-site scripting issue in Dotclear 2.11.2 that affects admin/blogs.php and admin/users.php through the sortby and order parameters. NVD rates the issue at CVSS 3.0 6.1 (MEDIUM) and maps it to CWE-79.
- Vendor
- Dotclear
- Product
- CVE-2017-6446
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-05
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-05
- Advisory updated
- 2026-05-13
Who should care
Dotclear administrators, maintainers, and teams operating version 2.11.2 or any deployment that exposes the affected admin pages to authenticated users.
Technical summary
The NVD record identifies Dotclear 2.11.2 as vulnerable and classifies the weakness as CWE-79 (XSS). The published CVSS vector is CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N, indicating network reachability, low attack complexity, and user interaction. The supplied references include a vendor patch changeset, which is the strongest remediation signal in the corpus.
Defensive priority
Medium. Patch or upgrade promptly if you run Dotclear 2.11.2, because the affected issue sits in admin-facing request handling and can impact confidentiality and integrity after user interaction.
Recommended defensive actions
- Apply the Dotclear vendor patch referenced in the changeset link or upgrade to a version that includes the fix.
- Review server-side handling of the sortby and order parameters in admin/blogs.php and admin/users.php and ensure untrusted input is properly encoded or validated.
- Limit access to the admin interface to trusted users and networks where feasible.
- Monitor affected admin endpoints for unusual request patterns or evidence of injected content.
- If you use compensating controls such as a web application firewall, add coverage for the affected admin routes while you deploy the vendor fix.
Evidence notes
The corpus contains an NVD CVE record for CVE-2017-6446, a SecurityFocus reference, and a Dotclear changeset marked as a patch. NVD states the affected CPE is dotclear 2.11.2 and assigns CWE-79. The supplied material does not include the fixed version number or a detailed vendor advisory text.
Official resources
-
CVE-2017-6446 CVE record
CVE.org
-
CVE-2017-6446 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
-
Mitigation or vendor reference
[email protected] - Patch
Public CVE disclosure date: 2017-03-05. The NVD record supplied here was last modified on 2026-05-13.