A reflected XSS vulnerability in the policy tool return URL allowed attackers to inject malicious script via crafted links. The root cause was insufficient sanitization of URL parameters before reflection