Jfinal_CMS 5.1.0 allows attackers to use the feedback function to send malicious XSS code to the administrator backend and execute it.Referenceshttps://github.com/jflyfox/jfinal_cms/issues/32