Cross-site scripting (XSS) vulnerability in Fenriru (1) Sleipnir 2.5.17 R2 and earlier and (2) Grani 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search field in a search for additions to the Favorites section.
https://exchange.xforce.ibmcloud.com/vulnerabilities/38441
http://www.securityfocus.com/bid/26418
http://www.fenrir.co.jp/sleipnir/note.html
http://www.fenrir.co.jp/grani/note.html
http://secunia.com/advisories/27675