WebCTRL OEM 6.5 and prior is susceptible to a cross-site scripting vulnerability because the login portal does not sanitize the operatorlocale GET parameter.
id: CVE-2021-31682
info:
name: WebCTRL OEM <= 6.5 - Cross-Site Scripting
author: gy741,dhiyanes
...