Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumaddoninstaller) before 2.11.0.7 for FreePBX allow remote attackers to inject arbitrary web script or HTML via the (1) addlicensekey, (2) addlicensefirstname, (3) addlicenselastname, (4) addlicensecompany, (5) addlicenseaddress1, (6) addlicenseaddress2, (7) addlicensecity, (8) addlicensestate, (9) addlicensepostcode, (10) addlicensecountry, (11) addlicensephone, or (12) addlicenseemail parameter in an add-license-form page to admin/config.php.