CVE-2019-19210: XSS
Published Mar 16, 2020
·Updated
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<10.0.3
10.0.3
dolibarr Dolibarr>=3.0.0<10.0.3
Event History
Mar 16, 2020
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
Description
May 24, 2022
Advisory Published
05:11 PM
Frequently Asked Questions
1
What is the severity of CVE-2019-19210?
The severity of CVE-2019-19210 is medium (5.4).
2
How does CVE-2019-19210 allow XSS?
CVE-2019-19210 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
3
What software versions are affected by CVE-2019-19210?
Dolibarr ERP/CRM versions up to and exclusive of 10.0.3 are affected by CVE-2019-19210.
4
How can I fix CVE-2019-19210?
To fix CVE-2019-19210, upgrade Dolibarr ERP/CRM to version 10.0.3 or later.
5
Where can I find more information about CVE-2019-19210?
You can find more information about CVE-2019-19210 at the following references: 1. [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-19210) 2. [USD](https://herolab.usd.de/security-advisories/usd-2019-0052/) 3. [Dolibarr Forum](https://www.dolibarr.org/forum/dolibarr-changelogs)