Mautic before 3.3.4 contains a cross-site scripting vulnerability on the password reset page in the bundle parameter of the URL. An attacker can inject arbitrary script, steal cookie-based authentication credentials, and/or launch other attacks.
View the template here CVE-2021-27909.yaml
References:
https://github.com/mautic/mautic/security/advisories/GHSA-32hw-3pvh-vcvc