CVE-2019-16197 is a Cross-Site Scripting (XSS) vulnerability affecting Dolibarr ERP/CRM version 10.0.1. Specifically, the User-Agent HTTP header's value is improperly rendered as plain text within the HTML document in htdocs/societe/card.php, allowing for script injection. This vulnerability has a CVSS score of 6.1 (Medium), indicating it can be exploited remotely with low attack complexity, requiring user interaction, and potentially leading to limited impact on confidentiality and integrity. While not listed on the KEV catalog or Hot List, public exploit code is available via ExploitDB (EDB-47384). There is currently no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0.1CPE matchmatch criteria | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:10.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.