CVE-2019-19211: XSS
Published Mar 16, 2020
·Updated
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
Affected Software
2 affected componentsFixes available
composer/dolibarr/dolibarr<10.0.3
10.0.3
dolibarr Dolibarr>=3.0.0<10.0.4
Event History
Mar 16, 2020
CVE Published
via MITRE·02:57 PM
Data Sourced
via MITRE·02:57 PM
Description
May 24, 2022
Advisory Published
05:11 PM
Frequently Asked Questions
1
What is the vulnerability in Dolibarr ERP/CRM before 10.0.3?
The vulnerability is an Insufficient Filtering issue that can lead to XSS in user/card.php.
2
How severe is the vulnerability with ID CVE-2019-19211?
The severity of the vulnerability is medium with a CVSS score of 6.1.
3
Which software versions are affected by CVE-2019-19211?
Dolibarr ERP/CRM versions up to 10.0.3 are affected, as well as versions between 3.0.0 and 10.0.4.
4
How can I fix the vulnerability in Dolibarr ERP/CRM?
To fix the vulnerability, update Dolibarr ERP/CRM to version 10.0.3 or higher.
5
Where can I find more information about CVE-2019-19211?
You can find more information about CVE-2019-19211 on the NVD, HEROLAB, and Dolibarr websites.