CVE-2021-47906
MEDIUMBloofoxCMS 0.5.2.1 - Authenticated Stored Cross-Site Scripting in Articles Text Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47906. PoCs published by LiPeiYi.
AI-analyzed exploit summary This is a writeup describing a stored XSS vulnerability in BloofoxCMS versions 0.5.1.0 to 0.5.2.1. The exploit involves injecting malicious JavaScript into the 'text' parameter of an article, which executes when viewed by other users.
Description
BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal authenticated users' cookies.
Exploits (1)
This is a writeup describing a stored XSS vulnerability in BloofoxCMS versions 0.5.1.0 to 0.5.2.1. The exploit involves injecting malicious JavaScript into the 'text' parameter of an article, which executes when viewed by other users.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N