{"id":"CVE-2019-19210","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-19210","summary":"Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.","details":"Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.","published":"2020-03-16T14:54:33.000Z","modified":"2024-08-05T02:09:39.512Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.dolibarr.org/forum/dolibarr-changelogs"},{"type":"WEB","url":"https://herolab.usd.de/en/security-advisories/"},{"type":"WEB","url":"https://herolab.usd.de/security-advisories/usd-2019-0052/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2024-08-05T02:09:39.512Z"}}