Description
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.
Remediation
References
Related Vulnerabilities
WordPress CVE-2014-5203 Vulnerability (CVE-2014-5203)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9700)
Oracle JRE CVE-2023-22036 Vulnerability (CVE-2023-22036)
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-4018)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3273)