JavaScript injection via vulnerable CMS