nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47947 CVE-2021-47947
MEDIUM
Projectsend r1295 Stored Cross-Site Scripting via files-edit.php
Record summary
CVE-2021-47947 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Projectsend r1295 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting crafted input in the 'name' parameter of files-edit.php. Attackers can inject JavaScript payloads through the file name field that execute in the browser when the file is viewed by other users, particularly affecting System Administrator users on the Dashboard page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ProjectsendBrowse Projectsend / Projectsend | CVE List | r1295 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBProjectsend r1295 - 'name' Stored XSSExploitDB exploitby Abdullah KalaNot analyzed1 file
References
5ExploitDB-50240exploit
https://www.exploit-db.com/exploits/50240 Official Product Homepageproduct
https://www.projectsend.org/ Product Referenceproduct
https://www.projectsend.org/download/387 VulnCheck Advisory: Projectsend r1295 Stored Cross-Site Scripting via files-edit.phpThird-party advisory
https://www.vulncheck.com/advisories/projectsend-r1295-stored-cross-site-scripting-via-files-edit-php