There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user\'s mailbox with the wrong format. The response contains the user\'s previously entered email address.