Phlex vulnerable to Cross-site Scripting (XSS) via maliciously formed HTML attribute names and values (CVE-2024-32970) | HOL Guard CVE