Логотип exploitDog
bind:CVE-2021-47738
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-47738

Количество 2

Количество 2

nvd логотип

CVE-2021-47738

около 2 месяцев назад

CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-ggjj-xc5q-883p

около 2 месяцев назад

CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.

CVSS3: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-47738

CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-ggjj-xc5q-883p

CSZ CMS 1.2.7 contains a persistent cross-site scripting vulnerability that allows unauthorized users to embed malicious JavaScript in private messages. Attackers can send messages with script payloads in the user-agent header, which will execute when an admin views the message in the backend dashboard.

CVSS3: 6.4
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу