in /access/setup?type-conn, in connection name,parameter name will be injected into HTML content with out any filter.
if you set connection name just like a `localhost <img src="/" onerror="alert(1)">`, so this name will be injected into HTML content with out any filter.
暂无评论