The plugin does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters
View the template here CVE-2022-2219.yaml
References:
https://github.com/ARPSyndicate/cvemon