4.3
CVSSv2

CVE-2019-16197

Published: 16/09/2019 Updated: 17/11/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

dolibarr dolibarr erp\\/crm 10.0.1

Exploits

# Exploit Title: Dolibarr ERP/CRM 1001 - User-Agent Http Header Cross Site Scripting # Exploit Author: Metin Yunus Kandemir (kandemir) # Vendor Homepage: wwwdolibarrorg/ # Software Link: wwwdolibarrorg/downloads # Version: 1001 # Category: Webapps # Tested on: Xampp for Linux # CVE: CVE-2019-16197 # Software Description : Do ...
Dolibarr ERP-CRM version 1001 suffers from a user-agent cross site scripting vulnerability ...