CVE-2021-47738
MEDIUMCSZ CMS 1.2.7 - Stored Cross-Site Scripting via Private Message User-Agent Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47738. PoCs published by Metin Yunus Kandemir.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in CSZ CMS 1.2.7 by injecting malicious JavaScript via the User-Agent header in a private message. When the admin views the message, the payload executes in their browser context.
Description
CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in CSZ CMS 1.2.7 by injecting malicious JavaScript via the User-Agent header in a private message. When the admin views the message, the payload executes in their browser context.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N