First published: Tue Oct 15 2019(Updated: )
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via `user/note.php`.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <11.0.1 | 11.0.1 |
Dolibarr ERP & CRM | =10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17223 is a vulnerability that allows HTML injection in the Note field in Dolibarr ERP/CRM 10.0.2 via `user/note.php`.
CVE-2019-17223 has a severity keyword of medium and a severity value of 6.1.
The affected software is Dolibarr ERP/CRM 10.0.2.
To fix CVE-2019-17223, upgrade Dolibarr ERP/CRM to version 11.0.1 or later.
The CWE of CVE-2019-17223 is CWE-79 (Improper Neutralization of Input During Web Page Generation).