Kasseler CMS File Disclosure and Cross Site Scripting Vulnerabilities
Description
Two vulnerabilities have been identified in Kasseler CMS, which could be exploited by attackers to disclose sensitive informatino.
The first issue is caused by an input validation error in the "engine.php" script that does not validate the "file" parameter, which could be exploited to download arbitrary files from an affected server.
The second vulnerability is caused by an input validation error in the "engine.php" script when processing the "url" parameter, which could allow cross site scripting attacks.