CVE-2021-47981

MEDIUM

Quick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47981. PoCs published by Rahad Chowdhury.

AI-analyzed exploit summary This exploit demonstrates a CSRF to XSS vulnerability in Quick.CMS 6.7. It includes a functional HTML form that submits a crafted payload to the vulnerable endpoint, triggering XSS when an authenticated admin interacts with the form.

Description

Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript in victim browsers when the form is submitted.

Exploits (1)

exploitdb WORKING POC
by Rahad Chowdhury · textwebappsphp
https://www.exploit-db.com/exploits/50530

This exploit demonstrates a CSRF to XSS vulnerability in Quick.CMS 6.7. It includes a functional HTML form that submits a crafted payload to the vulnerable endpoint, triggering XSS when an authenticated admin interacts with the form.

Classification
Working Poc 95%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Quick.CMS 6.7
Auth required
Prerequisites: Authenticated admin session · Victim interaction with malicious HTML form
devstral-2 · analyzed May 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-50530
https://www.exploit-db.com/exploits/50530
Product product
Official Product Homepage
https://opensolution.org/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Quick.CMS 6.7 Cross-Site Scripting via CSRF to Sliders Form
https://www.vulncheck.com/advisories/quick-cms-cross-site-scripting-via-csrf-to-sliders-form

Scores

CVSS v3 5.4
EPSS 0.0018
EPSS Percentile 7.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Opensolution/Quick.CMS 6.7
Published May 16, 2026
Tracked Since May 16, 2026