CheckSec Canopy before 3.5.2 allows XSS attacks against the login page via the LOGIN_PAGE_DISCLAIMER parameter.Referenceshttps://www.checksec.com/canopy.htmlhttps://www.compass-security.com/en/research/advisorieshttps://www.compass-security.com/fileadmin/Research/Advisories/2021-10_CSNC-2021-015-Checksec_Canopy_HTLM_Injection.txt