VulnerabilityAnalyzed
CVE-2021-47737
CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles.
MEDIUM 5.1EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.
- CVSS 4.0
- 5.1 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.28% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- cszcms/csz cms
- Source
- disclosure@vulncheck.com
References
- https://sourceforge.net/projects/cszcms/Product
- https://www.cszcms.com/Product
- https://www.exploit-db.com/exploits/48357Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/csz-cms-html-injection-vulnerability-via-member-dashboardThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.