Description
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
Remediation
References
Related Vulnerabilities
Atlassian Jira CVE-2019-11583 Vulnerability (CVE-2019-11583)
WordPress Plugin Product Reviews Import Export for WooCommerce Cross-Site Request Forgery (1.3.2)
XWiki Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2021-32729)
Joomla! Core 1.6.x Cross-Site Scripting (1.6.0 - 1.6.6)
Squid Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2019-18677)