Description
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.
Remediation
References
Related Vulnerabilities
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4226)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-44040)
WordPress Plugin MailPoet Newsletters (Previous) Arbitrary File Upload (2.6.7)
WordPress Plugin LearnDash LMS Arbitrary File Upload (2.5.3)