XSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=siteattachment attachmenturl parameter.