CVE-2019-19206: XSS
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
Other sources
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-19206?
CVE-2019-19206 is a vulnerability in Dolibarr CRM/ERP 10.0.3 that allows for Stored XSS due to JavaScript execution in an SVG image for a profile picture.
How severe is CVE-2019-19206?
CVE-2019-19206 has a severity score of 5.4, which is considered medium.
What software versions are affected by CVE-2019-19206?
Dolibarr CRM/ERP 10.0.3 is the only version affected by CVE-2019-19206.
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-19206?
CVE-2019-19206 is classified under CWE-79, which is the Cross-Site Scripting (XSS) vulnerability category.
How can I fix CVE-2019-19206?
To fix CVE-2019-19206, it is recommended to update Dolibarr CRM/ERP to a version that includes the necessary security patches.