ManageEngine ADSelfService Plus before 6121 contains a stored cross-site scripting vulnerability via the welcome name attribute to the Reset Password, Unlock Account, or User Must Change Password screens.
id: CVE-2022-24681
info:
name: ManageEngine ADSelfService Plus <6121 - Stored Cross-Site Scriptin
...