An issue was discovered in DiliCMS 2.4.0. There is a Stored XSS Vulnerability in the first textbox of "System setting->site setting" of admin/index.php, aka site_name.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-8438.json"