Coastercms v5.8.18 is affected by cross-site Scripting (XSS). A user can steal a cookie and make the user redirect to any malicious website because it is trigged on the main home page of the product/application.Referenceshttp://coastercms.comhttp://demo.coastercms.org/admin/homehttp://demo.coastercms.org/admin/loginhttp://demo.coastercms.org/homepage/bloghttps://www.exploit-db.com/exploits/49181