Due to improper restriction, attackers could retrieve and read system files of the underlying server through the XML interface.
Due to improper input validation, a remote attacker could execute arbitrary commands on the target system.
Because of an authentication flaw an attacker would be capable of generating a web report that discloses sensitive information such as internal IP addresses, usernames, store names and other sensitive information.