Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkoutitem.php, bibliography/dlprint.php, bibliography/item.php, bibliography/itembarcodegenerator.php, bibliography/printedcard.php, circulation/loanrules.php, masterfile/author.php, masterfile/colltype.php, and masterfile/doclanguage.php and the quickReturnID field to circulation/ajaxaction.php.
Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the 'slims7cendana-master/template/default/detailtemplate.php' and 'slims7cendana-master/template/default-rtl/detailtemplate.php' URLs. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.