ManageEngine ADSelfService Plus before 6121 contains a stored cross-site scripting vulnerability via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screens.
View the template here CVE-2022-24681.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2022-24681