Description
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
Remediation
References
Related Vulnerabilities
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.3.12)
WordPress Multiple Cross-Site Scripting and SQL Injection Vulnerabilities (1.2.1 - 1.2.2)
WordPress Plugin WP Shop Multiple SQL Injection Vulnerabilities (3.4.3.15)
WordPress Plugin Compact WP Audio Player Multiple Vulnerabilities (1.9.6)