Cross-site scripting (XSS) vulnerability in Sawmill 7.0.0 through 7.1.13 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP GET request.
https://exchange.xforce.ibmcloud.com/vulnerabilities/22206
http://www.sawmill.net/version_history.html
http://securityreason.com/securityalert/1