A stored cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of HPE Networking Fabric Composer. The vulnerability allows an authenticated low-privilege operator user to inject malicious scripts that target administrative users of the interface. A successful exploit enables the attacker to execute arbitrary script code within the victim's browser in the context of the affected interface. The attack requires authentication as a low-privilege user, lowering the barrier for exploitation in environments with multiple user roles. This type of privilege escalation via XSS can lead to session hijacking, credential theft, or further compromise of the administrative account. HPE has published a security bulletin addressing this issue. The vulnerability is currently awaiting full analysis by NVD.