

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

Source: CVE-2019-16688

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다