CVE-2019-19212: XSS
Published Mar 16, 2020
·Updated
Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
Affected Software
2 affected components
composer/dolibarr/dolibarr>=3.0<=10.0.3
dolibarr Dolibarr>=3.0.0<=10.0.3
Event History
Mar 16, 2020
CVE Published
via MITRE·07:48 PM
Data Sourced
via MITRE·07:48 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:11 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-19212.
2
What is the severity of CVE-2019-19212?
The severity of CVE-2019-19212 is critical with a severity value of 9.8.
3
What is the affected software?
The affected software is Dolibarr ERP/CRM versions 3.0 through 10.0.3.
4
How does CVE-2019-19212 exploit work?
The exploit for CVE-2019-19212 allows XSS (Cross-Site Scripting) by manipulating the 'qty' parameter in the 'product/fournisseurs.php' file.
5
How can I mitigate or fix CVE-2019-19212?
To mitigate or fix CVE-2019-19212, it is recommended to apply the latest security updates or patches provided by Dolibarr.