CVE-2020-29053

HRSALE 2.0.0 allows XSS via the admin/project/projects_calendar set_date parameter.