Dolibarr 3.5 / 3.6 HTML Injection

Dolibarr versions 3.5 and 3.6 suffer from an html injection vulnerability.