Description
Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
Remediation
References
Related Vulnerabilities
Dolibarr Improper Input Validation Vulnerability (CVE-2013-2093)
Python Integer Overflow or Wraparound Vulnerability (CVE-2017-1000158)
WordPress Plugin WPE Indoshipping Multiple Remote File Inclusion Vulnerabilities (2.5.0)
WordPress Plugin Pluginception Multiple Cross-Site Scripting Vulnerabilities (1.2)