Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-11823 - Vulnerability Database

Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-11823

Medium
Reference: CVE-2020-11823
Title: Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

In Dolibarr 10.0.6 if USER_LOGIN_FAILED is active there is a stored XSS vulnerability on the admin tools --gt audit page. This may lead to stealing of the admin account.