Description
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
Remediation
References
Related Vulnerabilities
WordPress Plugin Simple Sitemap-Create a Responsive HTML Sitemap Cross-Site Scripting (3.5.7)
WordPress Plugin Contact Form by BestWebSoft Cross-Site Scripting (3.51)
Contao Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-10642)
WordPress 3.9.x Denial of Service Vulnerability (3.9 - 3.9.23)