A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the Observations field. The flaw occurs in the History view, where historical data is rendered without proper HTML entity encoding. This allows an attacker to execute arbitrary JavaScript in the browser of viewing the history by administrators.
When an administrator views the History tab of that specific note, the script executes in their browser session.
Log in as a regular user.
Open "Sales"=>"Customers"=> "Delivery Notes"
<img width="818" height="223" alt="image" src="https://github.com/user-attachments/assets/82518644-2676-42db-93b1-86133986276c" />Chose one of the customer or create the new one.
Open "Delivery notes"
<img width="2078" height="713" alt="image" src="https://github.com/user-attachments/assets/f7e5027f-e574-4807-9e9c-bf8a51bc1fff" />Create a new Delivery Note or edit an existing one. Fill the "Number 2" field with any value and save.
<img width="2097" height="739" alt="image" src="https://github.com/user-attachments/assets/a3ca5ccb-3d9a-4cfc-a991-16206a1a862b" />Exploitability
AV:NAC:LPR:LUI:RScope
S:UImpact
C:HI:HA:H8.0/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H