JIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows attackers to arbitrarily add an administrator cookie.
- https://github.com/Cherry-toto/jizhicms
No PoCs found on GitHub currently.