out/out.UsrMgr.php in SeedDMS prior to 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
seeddms seeddms