CVE-2021-40868
In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
Date published : 2021-09-21
http://packetstormsecurity.com/files/164255/Cloudron-6.2-Cross-Site-Scripting.html
https://packetstormsecurity.com/files/164183/Cloudron-6.2-Cross-Site-Scripting.html