PT-2019-14573 · Dolibarr · Dolibarr
Published
2019-09-16
·
Updated
2022-11-17
·
CVE-2019-16197
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Dolibarr version 10.0.1
Description
The issue concerns the copying of the User-Agent HTTP header value into an HTML document as plain text between tags, leading to a potential XSS issue.
Recommendations
For Dolibarr version 10.0.1, consider modifying the htdocs/societe/card.php file to properly sanitize the User-Agent HTTP header value before it is copied into the HTML document to prevent XSS.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dolibarr