In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.Referenceshttps://bugs.eclipse.org/bugs/show_bug.cgi?id=546816