JIZHICMS 1.5.1 contains a cross-site scripting (XSS) vulnerability in the component /user/release.html, which allows attackers to arbitrarily add an administrator cookie.Referenceshttps://github.com/Cherry-toto/jizhicmshttps://github.com/Cherry-toto/jizhicms/issues/16