Description
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
Remediation
References
Related Vulnerabilities
WordPress Plugin FireStats 'firestats-wordpress.php' Remote File Include (1.6.1)
WordPress Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2014-6412)
WeBid Server-Side Request Forgery (SSRF) Vulnerability (CVE-2022-41477)
WordPress Plugin OAuth client Single Sign On for WordPress (OAuth 2.0 SSO) Security Bypass (3.0.3)