resources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter.Referenceshttps://github.com/openark/orchestrator/pull/1313https://github.com/openark/orchestrator/releases/tag/v3.2.4https://www.youtube.com/watch?v=DOYm0DIS3Us