XSS exists in the login_form function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATH_INFO to main.php.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected