Dolibarr before 7.0.2 is vulnerable to cross-site scripting and allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.
id: CVE-2018-10095
info:
name: Dolibarr <7.0.2 - Cross-Site Scripting
author: pikpikcu
severi
...