Jeesns 1.4.2 /newVersion cross site scripting