CMS Pylot Cross Site Request Forgery / Cross Site Scripting

CMS Pylot suffers from cross site request forgery and cross site scripting vulnerabilities.