The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
Credits
Adham Khairy Ramadan discovered and reported this vulnerability to AVEVA through a private HackerOne bug bounty program.