Description
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.
Remediation
References
Related Vulnerabilities
WordPress Plugin Directories Pro Cross-Site Scripting (1.3.45)
WordPress Plugin CWIS-Antivirus Security Scanner Unspecified Vulnerability (2.3.2)
WordPress Plugin Greenshift-animation and page builder blocks Cross-Site Scripting (4.9.9)
WordPress Plugin ThreeWP Email Reflector 'Subject' Field Cross-Site Scripting (1.15)