CVE-2021-47981
MEDIUMQuick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47981. PoCs published by Rahad Chowdhury.
AI-analyzed exploit summary This exploit demonstrates a CSRF to XSS vulnerability in Quick.CMS 6.7. It includes a functional HTML form that submits a crafted payload to the vulnerable endpoint, triggering XSS when an authenticated admin interacts with the form.
Description
Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript in victim browsers when the form is submitted.
Exploits (1)
This exploit demonstrates a CSRF to XSS vulnerability in Quick.CMS 6.7. It includes a functional HTML form that submits a crafted payload to the vulnerable endpoint, triggering XSS when an authenticated admin interacts with the form.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N