Description
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
Remediation
References
Related Vulnerabilities
WordPress Plugin Appointments Cross-Site Scripting (2.2.2.2)
Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3923)
WordPress Plugin WooCommerce Cross-Site Scripting (2.4.8)
MySQL CVE-2018-2667 Vulnerability (CVE-2018-2667)
WordPress Plugin Merge+Minify+Refresh Cross-Site Request Forgery (1.10.6)