Cross-site scripting (XSS) vulnerability in the captive portal in PacketFence before 3.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/74887
http://www.securityfocus.com/bid/53027
http://sourceforge.net/mailarchive/message.php?msg_id=29126135