Description
An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.
Remediation
References
Related Vulnerabilities
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1447)
Oracle Database Server CVE-2014-6541 Vulnerability (CVE-2014-6541)
Jenkins Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-27900)
WordPress Plugin Language Bar Flags Cross-Site Request Forgery (1.0.8)