CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks. | |
| Title | CSZ CMS 1.2.7 HTML Injection Vulnerability via Member Dashboard | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-23T21:08:02.702Z
Reserved: 2025-12-23T13:24:04.580Z
Link: CVE-2021-47737
Updated: 2025-12-23T21:07:59.269Z
Status : Received
Published: 2025-12-23T20:15:45.587
Modified: 2025-12-23T20:15:45.587
Link: CVE-2021-47737
No data.
OpenCVE Enrichment
No data.