CVE-2021-28418

MEDIUM

Seo Panel 4.8.0 - Cross-Site Scripting via Category Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-28418. PoCs published by Piyush Patil.

AI-analyzed exploit summary This exploit demonstrates a reflected XSS vulnerability in Seo Panel 4.8.0 via the 'category' parameter. The payload injects JavaScript that triggers an alert with the document cookie when the mouse hovers over the 'Cancel' field.

Description

A cross-site scripting (XSS) issue in Seo Panel 4.8.0 allows remote attackers to inject JavaScript via settings.php and the "category" parameter.

Exploits (1)

exploitdb WORKING POC
by Piyush Patil · textwebappsphp
https://www.exploit-db.com/exploits/49932

This exploit demonstrates a reflected XSS vulnerability in Seo Panel 4.8.0 via the 'category' parameter. The payload injects JavaScript that triggers an alert with the document cookie when the mouse hovers over the 'Cancel' field.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Seo Panel 4.8.0
Auth required
Prerequisites: Access to the SEO admin panel · User interaction (hovering over the 'Cancel' field)
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/seopanel/Seo-Panel/issues/207
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/162914/Seo-Panel-4.8.0-Cross-Site-Scripting.html

Scores

CVSS v3 4.8
EPSS 0.0187
EPSS Percentile 76.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
seopanel/seo_panel 4.8.0
Published Mar 18, 2021
Tracked Since Feb 18, 2026