A low-privilege user can inject a malicious XSS payload into the Metasys UI via a crafted URL. The payload persists across logins and executes in the browser context of other users, including administrators.
https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-14