Attackers can exploit these issues to run arbitrary code within the context of the site. This may allow attackers to steal cookie-based authentication credentials and to launch other attacks.
Vendor Status:
The vendor released an update to address this issue.