OpenText Carbonite Server Backup Portal before 8.8.7 allows XSS by an authenticated user via policy creation.

By admin