QSAN Storage Manager before 3.3.3 contains a reflected cross-site scripting vulnerability. Header page parameters do not filter special characters. Remote attackers can inject JavaScript to access and modify specific data.
View the template here CVE-2021-37216.yaml
References:
https://www.twcert.org.tw/tw/cp-132-4962-44cd2-1.html