Another XSS attack is possible if you put this in the login box as username
and pw:
<IMG SRC=javascript:alert('XSS')>
project.php is vulnerable too due to the input boxes on it for posting a
new project.
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.