There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-17223.json"