paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.shop.php (id parameter).Referenceshttps://github.com/paintballrefjosh/MaNGOSWebV4/issues/19http://www.securityfocus.com/bid/96939