CIVI-SA-2021-01: Reflected Cross Site Scripting via Uploaded CSVs
When importing data from CSV, the user's browser could be tricked into executing Javascript.
This vulnerability does not escalate the permissions of the user. However, if the user imports data from another application/system, then it could be used for an attack.