SiteVision suffers from an issue where attacker may inject non-authorized module when editing pages using a lower privileged account, which can lead to cross site scripting and remote code execution. All versions of SiteVision 4 until 4.5.6 and all versions of SiteVision 5 until 5.1.1 are vulnerable.
569aa7a3951f87f5f260db3ea1c088e5b8a42c0b4a4fa0174b6ff9408c9cc459