The 'login_form' function of the view/helpers.php file in the previous version of Phamm 0.6.7 has cross-site scripting vilnerabilities. A remote attacker can exploit this vulneraility to inject arbitrary web scripts or HTML. This rule supports to defend the A6: Vulnerable and Outdated Components and A3: Injection of OWASP Top 10 - 2021. Other reference:None