{"id":"CVE-2016-1912","details":"Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.","aliases":["GHSA-jh5p-wpg2-8rgv"],"modified":"2026-08-07T14:48:13.947342Z","published":"2016-01-15T20:59:04.363Z","references":[{"type":"WEB","url":"https://twitter.com/MickaelDorigny/status/684456187870457857"},{"type":"FIX","url":"https://github.com/GPCsolutions/dolibarr/commit/0d3181324c816bdf664ca5e1548dfe8eb05c54f8"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/135201/Dolibarr-3.8.3-Cross-Site-Scripting.html"},{"type":"EVIDENCE","url":"http://www.information-security.fr/xss-dolibarr-version-3-8-3/"},{"type":"EVIDENCE","url":"https://github.com/Dolibarr/dolibarr/issues/4341"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dolibarr/dolibarr","events":[{"introduced":"0"},{"last_affected":"74be7bf334c5407e43d3eddccfd61581487acd65"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"3.8.2"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:dolibarr:dolibarr:*:*:*:*:*:*:*:*"}}],"versions":["3.8.2","3.8.0","3.8.0-beta","3.7.1","3.7.0","3.6.2","3.6.1","3.6.0","3.6.0-beta","3.6.beta1_20140514","3.6.0-alpha","3.5.beta1_20131120","3.5.beta1_20131106","3.4.beta1_20130502","3.4.beta1_20130429","3.3.beta1_20121221"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1912.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/gpcsolutions/dolibarr","events":[{"introduced":"0"},{"fixed":"0d3181324c816bdf664ca5e1548dfe8eb05c54f8"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-1912.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}