Description
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
Remediation
References
Related Vulnerabilities
WordPress Plugin Sell Media Cross-Site Request Forgery (2.5.5)
PostgreSQL Out-of-bounds Read Vulnerability (CVE-2019-10209)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2016-8627)
Jenkins Insufficient Verification of Data Authenticity Vulnerability (CVE-2015-7539)
CakePHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4399)