Dolibarr ERP/CRM up to and including 8.0.3 has /exports/export.php?datatoexport= XSS.
dolibarr dolibarr