Reflected XSS is possible in Subversion ALM for the enterprise until 8.8.2. The software is vulnerable to reflected cross-site scripting attacks at several spots due to insufficient input sanitization.