Add a book info,book name input <img src=1 onerror=alert("xss1") />  Then the book list page alert the message: xss1 