Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags (CVE-2024-32463) | HOL Guard CVE