ManageEngine SelfService Plus Cross Site Scripting

ManageEngine SelfService Plus build 5312 (Mar 2016) and newer suffer from a cross site scripting vulnerability.