CVE-2021-47907
MEDIUMRocket LMS 1.1 Persistent Cross-Site Scripting via Support Tickets
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47907. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary This is a detailed technical writeup describing a persistent XSS vulnerability in Rocket LMS 1.1, including the vulnerable parameter, affected module, and proof-of-concept payload. It provides HTTP request logs and affected code snippets.
Description
Rocket LMS 1.1 contains a persistent cross-site scripting vulnerability in the support ticket module that allows authenticated users to inject malicious script code through the title parameter. Attackers can submit support tickets with embedded HTML/JavaScript payloads that execute in the browsers of other users viewing the message history, enabling session hijacking and phishing attacks.
Exploits (1)
This is a detailed technical writeup describing a persistent XSS vulnerability in Rocket LMS 1.1, including the vulnerable parameter, affected module, and proof-of-concept payload. It provides HTTP request logs and affected code snippets.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N