CVE-3: tradePay Unauthorized Invocation
CWE-940 | CVSS 8.6 | Payment dialog triggered from external page
Safety: This test uses an INVALID order string "SECURITY_TEST_INVALID_ORDER_2026".
No real transaction will occur. The proof is that the payment dialog appears at all —
an external page should NEVER be able to invoke tradePay.
Waiting for AlipayJSBridge...