An issue was discovered in VERMEG AgileReporter 21.3. Attackers can gain privileges via an XSS payload in an Add Comment action to the Activity log.
https://www.vermeg.com/agile-reporter/
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37740
https://crashpark.weebly.com/blog/2-stored-xss-in-agilereporter-213-by-vermeg