I. It seems that someone has reflected it before. It appears in the QQ mail body hyperlink Editor, which is a reflective xss, which is very rare. I just saw that the TSRC platform launched the gift exchange platform to join in. Cainiao, hope to encourage me ~
Ii. Test code
<Iframe onload = alert (/qq/);> enter any text in the body, Select Insert hyperlink, and enter <iframe onload = alert (/qq/);> click Add to trigger xss. Click the link text to trigger it again. It is not over yet. Add a hyperlink without entering text and construct an iframe framework in the text area. <iframe src % 3 dhttp % 3a // www.afeng.org/1.html> may not be very successful, but the framework came out. I do not know the exploitation, nor will I construct it further. Although it is very rare, there is no use of value, do not wait until it is used to repair...
Iii. solution:
You know more about the solution than I do.