Cross Site Scripting (XSS) vulnerability in HongCMS 3.0 allows attackers to run arbitrary code via the callback parameter to /ajax/myshop.Referenceshttps://github.com/Neeke/HongCMS/issues/15