Description
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
Remediation
References
Related Vulnerabilities
Internet Information Services Other Vulnerability (CVE-1999-1035)
Internet Information Services Other Vulnerability (CVE-1999-1223)
LimeSurvey CVE-2019-16176 Vulnerability (CVE-2019-16176)
WordPress Plugin Visitor Traffic Real Time Statistics Security Bypass (2.11)
Ruby Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2011-1004)