Description
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP-Filebase Download Manager Multiple Unspecified Vulnerabilities (0.2.9.24)
Drupal Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-13674)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-4112)
Oracle Database Server CVE-2020-2737 Vulnerability (CVE-2020-2737)