Cross-site scripting (XSS) vulnerability in templates/installer/step-004.inc.php in spotweb 1.5.1 and below allow remote attackers to inject arbitrary web script or HTML via the newpassword2 parameter.
id: CVE-2021-40968
info:
name: Spotweb <= 1.5.1 - Cross Site Scripting
author: theamanrawat
s
...