Description
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.
Remediation
References
Related Vulnerabilities
WordPress Plugin LOGIN AND REGISTRATION ATTEMPTS LIMIT Cross-Site Request Forgery (2.1)
WordPress Improper Input Validation Vulnerability (CVE-2008-5695)
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2009-3294)
WordPress Plugin Master Slider-Responsive Touch Slider SQL Injection (2.5.1)