Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-17576
An issue was discovered in Dolibarr 10.0.2. It has XSS via the quotoutgoing email setupquot feature in the /admin/mails.phpactionedit URI via the quotSend all emails to (instead of real recipients for test purposes)quot field.