Detection and Exploitation:
- Login to the dashboard
- Go to Racks and click on the action button => add a new book or edit book
- Inject payload : "' test <img src="" onerror="alert(5)"> to Title of book parameter and submit it.
- Go to Borrowing and add a new Borrowing or edit Borrowring then malicious is execute