Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-13828 - Vulnerability Database

Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-13828

Medium
Reference: CVE-2020-13828
Title: Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.phpactioncreate with the subject message or address parameter adherents/card.php with the societe or address parameter product/card.php with the label or customcode parameter or societe/card.php with the alias or barcode parameter.