When common user send this malicious URL to the web manager and request it, the web manager could be executed the malicious javascript code [XSRF.Vulnerability.exists.in.the.file.of.DedeCMS.V5.7sp2.pdf](https://github.com/ky-j/dedecms/files/4553296/XSRF.Vulnerability.exists.in.the.file.of.DedeCMS.V5.7sp2.pdf) __Originally posted by @TaroballzChen in https://github.com/ky-j/dedecms/issues/12__