php-mod/curl (a wrapper of the PHP cURL extension) before 2.3.2 allows XSS via the postfilepathupload.php key parameter and the POST data to postmultidimensional.php.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-30134.json"