CVE-2021-47737

MEDIUM

CSZ CMS 1.2.7 - Authenticated HTML Injection via Member Messaging System

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47737. PoCs published by Metin Yunus Kandemir.

AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in CSZ CMS 1.2.7, where an authenticated user can inject a hyperlink into the Backend System Dashboard and Member Dashboard via a crafted message. The PoC shows a POST request with a malicious 'title' parameter containing an HTML anchor tag.

Description

CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.

Exploits (1)

exploitdb WORKING POC
by Metin Yunus Kandemir · textwebappsphp
https://www.exploit-db.com/exploits/48357

This exploit demonstrates an HTML injection vulnerability in CSZ CMS 1.2.7, where an authenticated user can inject a hyperlink into the Backend System Dashboard and Member Dashboard via a crafted message. The PoC shows a POST request with a malicious 'title' parameter containing an HTML anchor tag.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: CSZ CMS v1.2.7
Auth required
Prerequisites: Authenticated user access · Valid CSRF token
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry exploit
https://www.exploit-db.com/exploits/48357
Product product
https://www.cszcms.com/

Scores

CVSS v3 5.4
EPSS 0.0024
EPSS Percentile 15.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
Cszcms/CSZ CMS 1.2.7
cszcms/csz_cms 1.2.7
Published Dec 23, 2025
Tracked Since Feb 18, 2026