This PoC performs XSS attack via newMessage parameter (a POST variable) in sendingmessage.php.
XSS vulnerabilities