Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/myfriend.php ftype parameter.Referenceshttps://github.com/ky-j/dedecms/issues/10