Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://github.com/Dolibarr/dolibarr/releases | third party advisory release notes |
https://trovent.io/security-advisory-2105-02 | third party advisory exploit |
https://trovent.github.io/security-advisories/TRSA-2105-02/TRSA-2105-02.txt | third party advisory exploit |
http://seclists.org/fulldisclosure/2021/Nov/38 | third party advisory mailing list |