An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field.Referenceshttps://www.exploit-db.com/exploits/44546/https://github.com/rainlab/user-plugin/commit/098c2bc907443d67e9e18645f850e3de42941d20