MEDIUM
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php
Published Oct 15, 2019
6.1
MEDIUMCVSS 3.1
EPSS 1.11%
Description
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
Affected products
No data.
- 10.0.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (8)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2079 Advisory
- https://github.com/Dolibarr/dolibarr/commit/c7736dde41826ac6eca3e838e57eab2f0304e256
- https://github.com/advisories/GHSA-3264-65pg-5xm4 Advisory
- https://medium.com/%40k43p/cve-2019-17223-stored-html-injection-dolibarr-crm-erp-ad1e064d0ca5 x_refsource_MISC
- https://medium.com/@k43p/cve-2019-17223-stored-html-injection-dolibarr-crm-erp-ad1e064d0ca5
- https://nvd.nist.gov/vuln/detail/CVE-2019-17223
- https://security.snyk.io/vuln/SNYK-PHP-DOLIBARRDOLIBARR-473217
- https://www.dolibarr.org/forum/dolibarr-changelogs x_refsource_MISCRelease NotesVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 15, 2019
Updated Aug 5, 2024
Reserved Oct 6, 2019
Link CVE-2019-17223
CISA Vulnrichment
No data
Red Hat
No data
GitHub
Link GHSA-3264-65PG-5XM4