Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.
{ "binaries": [ { "binary_version": "3.5.8+dfsg1-1ubuntu1", "binary_name": "dolibarr" } ] }