The /edit URI in the DMS component in Ximdex 4.0 has XSS via the Ciudad or Nombre parameter.Referenceshttps://github.com/XIMDEX/ximdex/issues/149