# reflective xss in /application/admin/controller/User.php via call_back for function doSendMail
in `/application/admin/controller/User.php` line 541, parameter call_back be displayed in javacript script without any filter.
payload:
```
call_back=alert(321321);//
```
暂无评论