Description
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.
Remediation
References
Related Vulnerabilities
WordPress Plugin 5gig Concerts Unspecified Vulnerability (1.0)
WordPress Plugin Custom Field Template PHP Object Injection (2.5.7)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10268)
Liferay Portal URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2022-28977)
WordPress Plugin WP PRO Advertising System-All In One Ad Manager SQL Injection (4.6.18)