Reflected XSS affects the ‘mode’ parameter in the /admin functionality of the web application in versions <=2.0.44