PT-2025-52837 · Csz Cms · Csz Cms

Published

2025-12-23

·

Updated

2025-12-23

·

CVE-2021-47737

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CSZ CMS version 1.2.7
Description An HTML injection issue exists in CSZ CMS that permits authenticated users to inject malicious hyperlinks into message titles. Attackers can create POST requests to the member messaging system using HTML-based links, potentially enabling phishing or social engineering attacks. The vulnerability affects the member messaging system. The vulnerable parameter is the message title.
Recommendations Apply updates to address the HTML injection issue in message titles.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47737

Affected Products

Csz Cms