Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace