initLayoutType of the file examples/session_example.php of the component Example. Executing manipulation of the argument $_SERVER['PHP_SELF'] can lead to cross site scripting.This vulnerability is registered as CVE-2018-25080. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is advisable to upgrade the affected component.