Medium severity5.4NVD Advisory· Published Nov 26, 2019· Updated Jun 17, 2026
CVE-2019-19206
CVE-2019-19206
Description
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dolibarr/dolibarrPackagist | <= 10.0.3 | — |
Affected products
3- Dolibarr/Dolibarr CRM/ERPdescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-f6h3-66xr-hqr2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-19206ghsaADVISORY
- www.dolibarr.org/forum/dolibarr-changelogsnvdRelease NotesVendor AdvisoryWEB
- medium.com/@k43p/cve-2019-19206-stored-xss-due-to-javascript-execution-in-an-svg-file-ee1d038fba76ghsaWEB
- medium.com/%40k43p/cve-2019-19206-stored-xss-due-to-javascript-execution-in-an-svg-file-ee1d038fba76nvd
News mentions
0No linked articles in our index yet.