Web-pages which use the "Resources" API to inject JSON data ("settings") may create vectors for XSS attacks.
CiviCRM version 5.74.3 and earlier
CiviCRM version 5.74.4 and 5.69.6 (ESR)
Upgrade to the fixed version of CiviCRM
Wikimedia Foundation - Eileen McNaughton; CiviCRM - Tim Otten, Coleman Watts
security/core!171