Redwood Report2Web 4.3.4.5 and 4.5.3 contains a cross-site scripting vulnerability in the login panel which allows remote attackers to inject JavaScript via the signIn.do urll parameter.
View the template here CVE-2021-26710.yaml
References:
https://github.com/ARPSyndicate/cvemon