Record summary

CVE-2021-47947 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input in the 'name' parameter of files-edit.php. Attackers can inject JavaScript payloads through the file name field that execute in the browser when the file is viewed by other users, particularly affecting System Administrator users on the Dashboard page.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE Listr1295affected

Proofs of concept

1

Catalogued exploits

ExploitDBProjectsend r1295 - 'name' Stored XSSExploitDB exploitby Abdullah KalaNot analyzed1 file
ExploitDB

PoC details

References

5