zzcms 8.3 Download link:

Vulnerability location

/uploadimg_form.php line 66 noshuiyin parameter Directly from user input and no security filtering that cause a self_xss

Vulnerability trigger condition

Triggered after user or admin login


