Registered user login, comment on the article.
POC, <img src=x onerror=alert(1)>
Submit comment to grab packet,
use burp modify parameter pinglun=<img src=x onerror=alert(1)>
Browse article or administrator login background can trigger
The text was updated successfully, but these errors were encountered:
Registered user login, comment on the article.

POC,
<img src=x onerror=alert(1)>Submit comment to grab packet,
use burp modify parameter pinglun=
<img src=x onerror=alert(1)>Browse article or administrator login background can trigger
The text was updated successfully, but these errors were encountered: