Rumpus FTP Web File Manager 8.2.9.1 contains a reflected cross-site scripting vulnerability via the Login page. An attacker can send a crafted link to end users and can execute arbitrary JavaScript.
View the template here CVE-2019-19368.yaml
References:
https://github.com/harshit-shukla/CVE-2019-19368/