CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-014-03