First published: Tue Nov 26 2019(Updated: )
Dolibarr CRM/ERP 10.0.3 allows `viewimage.php?file=` Stored XSS due to JavaScript execution in an SVG image for a profile picture.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dolibarr/dolibarr | <=10.0.3 | |
Dolibarr Dolibarr Erp\/crm | =10.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19206 is a vulnerability in Dolibarr CRM/ERP 10.0.3 that allows for Stored XSS due to JavaScript execution in an SVG image for a profile picture.
CVE-2019-19206 has a severity score of 5.4, which is considered medium.
Dolibarr CRM/ERP 10.0.3 is the only version affected by CVE-2019-19206.
CVE-2019-19206 is classified under CWE-79, which is the Cross-Site Scripting (XSS) vulnerability category.
To fix CVE-2019-19206, it is recommended to update Dolibarr CRM/ERP to a version that includes the necessary security patches.