Summary
A stored cross-site scripting flaw in a management interface allowed attacker-controlled script to run in the context of other users.
The vulnerability
Describe the injection point, the missing output encoding, and the payload used to confirm execution.
Impact
Script execution in an admin context can lead to session theft and privileged actions — rated high.