CVE-2021-47834
MEDIUMSchlix CMS 2.2.6-6 - Authenticated Stored Cross-Site Scripting in Category Title
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47834. PoCs published by Emircan Baş.
AI-analyzed exploit summary This exploit demonstrates a persistent XSS vulnerability in Schlix CMS 2.2.6-6, where an authenticated attacker can inject malicious JavaScript into the 'title' field of a contact category, which executes when the page is visited.
Description
Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the page is viewed by other users.
Exploits (1)
This exploit demonstrates a persistent XSS vulnerability in Schlix CMS 2.2.6-6, where an authenticated attacker can inject malicious JavaScript into the 'title' field of a contact category, which executes when the page is visited.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N