There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remote attackers to inject arbitrary web script or HTML via the data[performredirect] parameter.
id: CVE-2021-43725
info:
name: Spotweb <= 1.5.1 - Cross Site Scripting (Reflected)
author: thea
...