CSZ CMS 1.2.7 HTML Injection Vulnerability via Member Dashboard
Vulnerability Description
CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47737
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Metin Yunus Kandemir
References
Affected Vendor
Cszcms
View all reports →