Security Advisory

CVE-2019-16688

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-09-27 19:14:27
Last updated 2024-08-05 01:17:41
Assigner mitre
State PUBLISHED

Description

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)