All versions of Maximus' iCue and iParent suffer from an input validation flaw that allows for cross site scripting.