Haraj 3.7 contains a cross-site scripting vulnerability in the User Upgrade Form. An attacker can inject malicious script and thus steal authentication credentials and launch other attacks.
View the template here CVE-2022-31299.yaml
References:
https://github.com/bigzooooz/CVE-2022-31299