Orangescrum version 1.6.1 suffers from cross site scripting and remote file upload vulnerabilities. Continue reading...