Description
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
Remediation
References
Related Vulnerabilities
Serendipity Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3800)
NuSOAP Improper Certificate Validation Vulnerability (CVE-2012-6071)
Serendipity Other Vulnerability (CVE-2005-1713)
WordPress Plugin Lightbox Gallery Cross-Site Scripting (0.9.4)
e107 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2018-17081)