VMware Aria Operations contains a stored cross-site scripting vulnerability. A malicious actor with editing access to cloud provider might be able to inject malicious script leading to stored cross-site scripting in the product VMware Aria Operations.
https://securityaffairs.com/171472/security/vmware-fixed-five-vulnerabilitiesaria-operations.html
https://www.securityweek.com/vmware-patches-high-severity-vulnerabilities-in-aria-operations/