CVE-2021-27695

Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbitrary web script or HTML via any «Add» sections, such as Add Card Building & Floor, or others in the Name and Code Parameters.