Description
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.
Remediation
References
Related Vulnerabilities
Drupal Core 8.4.x Remote Code Execution (8.4.0 - 8.4.7)
Sqlite Integer Overflow or Wraparound Vulnerability (CVE-2025-3277)
Joomla Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2005-4650)
phpMyFAQ Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2018-16651)
PrestaShop Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-15081)