In the event the question string consists of sensitive details such as session identifiers, then attackers can use this info to start even more attacks. as the obtain token in sent in GET requests, this vulnerability https://roxannopbp500047.mybuzzblog.com/9223601/the-greatest-guide-to-mysql-database-health-check-consultant