Ordinary users can add users to the user management system as well,
or change their own email address, which isn't properly sanitized, thus
allowing XSS as follows (for example):
<script>alert(document.cookie)</script>
Nomenumbra
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.