CMS Made Simple through 2.2.14 allows XSS via a crafted File Picker profile name.
- http://dev.cmsmadesimple.org/bug/view/12312
- https://www.youtube.com/watch?v=Q6RMhmpScho
- https://github.com/ARPSyndicate/cvemon