Description
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.
Remediation
References
Related Vulnerabilities
phpMyFAQ Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-5227)
MySQL CVE-2021-35622 Vulnerability (CVE-2021-35622)
Oracle Database Server CVE-2015-0373 Vulnerability (CVE-2015-0373)
Oracle JRE CVE-2013-5783 Vulnerability (CVE-2013-5783)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-7570)