An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-12625.json"