BIGACE 2.7.8 Cross Site Scripting / File Upload

BIGACE version 2.7.8 suffers from cross site scripting and file upload vulnerabilities.