admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAINMAXDECIMALS_TOT parameter.
{ "severity": "Medium", "cpes": [ "cpe:2.3:a:dolibarr:dolibarr_erp/crm:*:*:*:*:*:*:*:*" ] }
"https://github.com/bitnami/vulndb/tree/main/data/dolibarr/BIT-dolibarr-2022-22293.json"