Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex (CVE-2024-28199) | HOL Guard CVE