Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model parameter to index.php/admin/editor.
https://www.htbridge.com/advisory/HTB23172
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-5530
http://www.exploit-db.com/exploits/28557
http://archives.neohapsis.com/archives/bugtraq/2013-09/0117.html