CVE-2021-47737
MEDIUMCSZ CMS 1.2.7 - Authenticated HTML Injection via Member Messaging System
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47737. PoCs published by Metin Yunus Kandemir.
AI-analyzed exploit summary This exploit demonstrates an HTML injection vulnerability in CSZ CMS 1.2.7, where an authenticated user can inject a hyperlink into the Backend System Dashboard and Member Dashboard via a crafted message. The PoC shows a POST request with a malicious 'title' parameter containing an HTML anchor tag.
Description
CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.
Exploits (1)
This exploit demonstrates an HTML injection vulnerability in CSZ CMS 1.2.7, where an authenticated user can inject a hyperlink into the Backend System Dashboard and Member Dashboard via a crafted message. The PoC shows a POST request with a malicious 'title' parameter containing an HTML anchor tag.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N