A vulnerability, which was classified as problematic, has been found in Qool CMS 2.0. Affected is the function
addnewtype/addnewdatafield/addmenu/addusergroup/addnewuserfield/adduser/addgeneraldata/addcontentitem of the component POST Parameter Handler. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2013-20006. The attack may be initiated remotely. In addition, an exploit is available.