Description
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
Remediation
References
Related Vulnerabilities
WordPress Plugin Omni Secure Files 'upload.php' Arbitrary File Upload (0.1.13)
Dolibarr Other Vulnerability (CVE-2022-0414)
PHP Improper Input Validation Vulnerability (CVE-2016-7129)
WordPress Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-0682)
Apache Tomcat Improper Input Validation Vulnerability (CVE-2012-3544)