The product does not properly handle when all or part of an input has been URL encoded.
MITRE ATT&CK techniques associated with this weakness class (mapped via MITRE CAPEC). A vulnerability of this type could let an adversary carry out: