CVE-2021-47962

MEDIUM

Savsoft Quiz 5.0 Persistent Cross-Site Scripting via User Settings

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47962. PoCs published by strider.

AI-analyzed exploit summary The exploit demonstrates a persistent XSS vulnerability in Savsoft Quiz 5.0 by injecting malicious JavaScript into user account settings fields, which executes upon form submission.

Description

Savsoft Quiz 5.0 contains a persistent cross-site scripting vulnerability in the user account settings page that allows authenticated attackers to inject malicious HTML and JavaScript code. Attackers can inject script payloads into user profile fields at the edit_user endpoint, which execute in the browsers of users viewing the affected profile after submission.

Exploits (1)

exploitdb WORKING POC
by strider · textwebappsphp
https://www.exploit-db.com/exploits/49825

The exploit demonstrates a persistent XSS vulnerability in Savsoft Quiz 5.0 by injecting malicious JavaScript into user account settings fields, which executes upon form submission.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Savsoft Quiz 5.0
Auth required
Prerequisites: valid user account · access to user settings page
devstral-2 · analyzed May 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-49825
https://www.exploit-db.com/exploits/49825
Product product
Official Product Homepage
https://savsoftquiz.com
Product product
Product Reference
https://github.com/savsofts/savsoftquiz_v5
Third Party Advisory third-party-advisory
VulnCheck Advisory: Savsoft Quiz 5.0 Persistent Cross-Site Scripting via User Settings
https://www.vulncheck.com/advisories/savsoft-quiz-persistent-cross-site-scripting-via-user-settings

Scores

CVSS v3 6.4
EPSS 0.0024
EPSS Percentile 15.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
savsofts/Savsoft Quiz 5.0
Published May 15, 2026
Tracked Since May 16, 2026