Vulnerable Systems:
* eFront versions prior to 3.6.3 build 7400
Immune Systems:
* eFront version 3.6.3 build 7455
These issues are caused by input validation errors when processing the "remote_theme", "name", "system_email", "password_length", "math_server", "site_motto" and "site_name" parameters, which could be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.