Cross-site scripting (XSS) vulnerability in BosDev BosNews 4 allows remote malicious users to inject arbitrary web script or HTML via a SCRIPT element in a news post.
bosdev bosnews 4