Description
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
Remediation
References
Related Vulnerabilities
MongoDb Resource Management Errors Vulnerability (CVE-2013-3969)
WordPress Plugin WP Custom Fields Search Cross-Site Scripting (0.3.28)
Joomla CVE-2018-15881 Vulnerability (CVE-2018-15881)
PostgreSQL CVE-2023-5868 Vulnerability (CVE-2023-5868)
WordPress 2.1.1 Command Execution Backdoor Vulnerability (2.1.1)