CVE-2016-1912

NameCVE-2016-1912
DescriptionMultiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs812496

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
dolibarrsourcejessie3.5.5+dfsg1-1+deb8u1
dolibarrsource(unstable)3.5.8+dfsg1-1812496

Notes

https://github.com/Dolibarr/dolibarr/issues/4341

Search for package or bug name: Reporting problems