WebCTRL OEM 6.5 and prior is susceptible to a cross-site scripting vulnerability because the login portal does not sanitize the operatorlocale GET parameter.
View the template here CVE-2021-31682.yaml
References:
https://github.com/ARPSyndicate/cvemon