Description
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
Remediation
References
Related Vulnerabilities
SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2025-30382)
Ruby on Rails Improper Input Validation Vulnerability (CVE-2013-0156)
WordPress Plugin Service Finder-Provider and Business Listing Local File Disclosure (3.0)
WordPress Plugin Password Protected Unspecified Vulnerability (2.0)
WordPress Plugin NextCellent Gallery-NextGEN Legacy Cross-Site Scripting (1.9.17)