citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter).Referenceshttp://www.securityfocus.com/bid/98082https://github.com/citymont/symetrie/issues/3