Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-17578 - Vulnerability Database

Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2019-17578

Medium
Reference: CVE-2019-17578
Title: Dolibarr Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

An issue was discovered in Dolibarr 10.0.2. It has XSS via the quotoutgoing email setupquot feature in the admin/mails.phpactionedit URI via the quotSender email for automatic emails (default value in php.ini: Undefined)quot field.