First published: Mon Mar 16 2020(Updated: )
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dolibarr Dolibarr | >=3.0.0<10.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-19210 is medium (5.4).
CVE-2019-19210 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
Dolibarr ERP/CRM versions up to and exclusive of 10.0.3 are affected by CVE-2019-19210.
To fix CVE-2019-19210, upgrade Dolibarr ERP/CRM to version 10.0.3 or later.
You can find more information about CVE-2019-19210 at the following references: 1. [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-19210) 2. [USD](https://herolab.usd.de/security-advisories/usd-2019-0052/) 3. [Dolibarr Forum](https://www.dolibarr.org/forum/dolibarr-changelogs)