Description
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
Remediation
References
Related Vulnerabilities
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.24)
WordPress Plugin iThemes Exchange:Simple WP Ecommerce Remote Code Execution (1.14.0)
GibbonEdu CVE-2023-45878 Vulnerability (CVE-2023-45878)
WordPress Plugin Ultimate Affiliate Pro Multiple Cross-Site Scripting Vulnerabilities (3.6)