CVE-2019-16197: Dolibarr Erp/crm
Medium severity, CVSS 6.1. EPSS: 3% chance of exploitation in the next 30 days.
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
Affected products
- Dolibarr Dolibarr Erp/crm: version 10.0.1 only
Published 2019-09-16. Last modified 2026-06-17.