Description
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2016-0467 Vulnerability (CVE-2016-0467)
Dolibarr Improper Authentication Vulnerability (CVE-2020-7995)
Oracle HTTP Server Uncontrolled Resource Consumption Vulnerability (CVE-2022-25313)
Oracle Database Server Other Vulnerability (CVE-2005-0298)
IBM WebSEAL Improper Restriction of XML External Entity Reference Vulnerability (CVE-2019-4707)