please check this link: https://demo.go-admin.com/admin/login?ref=javascript:alert();// after successful login XSS will be fired