CVE-2019-19210
16.03.2020, 15:15
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
Vendor | Product | Version |
---|---|---|
dolibarr | dolibarr | 3.0.0 ≤ 𝑥 < 10.0.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References