ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.Referenceshttps://github.com/woider/ArticleCMS/issues/5