Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-17577 - Vulnerability Database

Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-17577

Medium
Reference: CVE-2019-17577
Title: Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

An issue was discovered in Dolibarr 10.0.2. It has XSS via the quotoutgoing email setupquot feature in the admin/mails.phpactionedit URI via the quotEmail used for error returns emails (fields 39Errors-To39 in emails sent)quot field.