Description
htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
Remediation
References
Related Vulnerabilities
WordPress Plugin Captchinoo, Google recaptcha for admin login page Cross-Site Request Forgery (2.4)
WordPress Plugin Cache-Control Unspecified Vulnerability (2.2.3)
IBM RTC Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2865)
Oracle HTTP Server Use of Insufficiently Random Values Vulnerability (CVE-2020-35163)