Description
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.
Remediation
References
Related Vulnerabilities
WordPress Plugin HK Exif Tags Cross-Site Scripting (1.11)
WordPress Plugin Database for Contact Form 7, WPforms, Elementor forms Cross-Site Scripting (1.1.5)
Magento CVE-2019-7896 Vulnerability (CVE-2019-7896)
WordPress Plugin WP-Ban Cross-Site Scripting (1.69)
WordPress Plugin Multicons [Multiple Favicons] Cross-Site Scripting (2.1)