An unauthenticated remote attacker could provide a malicious link and trick an unsuspecting user into clicking on it. If clicked, the attacker could execute the malicious JavaScript (JS) payload in the target’s security context.
https://www.cisa.gov/news-events/ics-advisories/icsa-23-082-03