cve/2019/CVE-2019-16687.md
2024-06-18 02:51:15 +02:00

678 B

CVE-2019-16687

Description

Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

POC

Reference

Github

No PoCs found on GitHub currently.