CVE-2019-16197
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
MEDIUM · CVSS 6.1
EPSS 0.00154
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0