Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated)
Vulnerability Description
Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the page is viewed by other users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47834
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Emircan Baş
References
Affected Vendor
Schlix
View all reports →