Description
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
Remediation
References
Related Vulnerabilities
Squid Operation on a Resource after Expiration or Release Vulnerability (CVE-2024-23638)
MySQL CVE-2020-14793 Vulnerability (CVE-2020-14793)
WordPress Plugin Oi Yandex.Maps for WordPress Cross-Site Scripting (3.2.7)
MySQL CVE-2018-3067 Vulnerability (CVE-2018-3067)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-1606)