Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- http://sourceforge.net/p/mydms/code/HEAD/tree/trunk/CHANGELOG
No PoCs found on GitHub currently.