Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.
No PoCs from references.
- https://github.com/Snowty/myCVE
- https://github.com/emh1tg/CraftCMS-2.6.3000
- https://github.com/eoo911/CraftCMS-2.6.3000