Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
References
Link | Resource |
---|---|
https://medium.com/@k43p/cve-2019-19206-stored-xss-due-to-javascript-execution-in-an-svg-file-ee1d038fba76 | Third Party Advisory |
https://www.dolibarr.org/forum/dolibarr-changelogs | Release Notes Vendor Advisory |
Configurations
Information
Published : 2019-11-26 07:15
Updated : 2022-11-17 09:21
NVD link : CVE-2019-19206
Mitre link : CVE-2019-19206
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
dolibarr
- dolibarr_erp\/crm