CVE-2019-16197: Dolibarr Erp/crm

Medium severity, CVSS 6.1. EPSS: 3% chance of exploitation in the next 30 days.

In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

Affected products

  • Dolibarr Dolibarr Erp/crm: version 10.0.1 only

Published 2019-09-16. Last modified 2026-06-17.