# ZZ_2024_8 backend data addition is vulnerable to XSS First, log in to the backend: ![image-20250221094010437](https://github.com/caigo8/picx-images-hosting/raw/master/image-20250221094010437.sz2vv1yxn.webp) Then click on the customer information in the customer management section. ![image-20250221094113680](https://github.com/caigo8/picx-images-hosting/raw/master/image-20250221094113680.wiotkv4t3.webp) Modify customer information Insert code at the username position. ![image-20250221094702458](https://github.com/caigo8/picx-images-hosting/raw/master/image-20250221094702458.3uuyx33gm9.webp) Save information Click the "Back" button Trigger XSS ![image-20250221094744780](https://github.com/caigo8/picx-images-hosting/raw/master/image-20250221094744780.5c13yu7n7j.webp)