Ametys is a Java-based open source CMS combining rich content with an easy-to-use and intuitive interface.
Input passed via the 'lang' POST parameter in the newsletter plugin is not properly sanitised before being used to construct a XPath query for XML data. This can be exploited to manipulate XPath queries by injecting arbitrary XPath code.