Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
https://gist.github.com/enferas/e8fff9261526fdf51808c39b3004e1b5
https://gist.github.com/enferas/e4ab1aedd9727c3b09c7d0154a052199