Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkoutitem.php, bibliography/dlprint.php, bibliography/item.php, bibliography/itembarcodegenerator.php, bibliography/printedcard.php, circulation/loanrules.php, masterfile/author.php, masterfile/colltype.php, and masterfile/doclanguage.php and the quickReturnID field to circulation/ajaxaction.php.