Security Advisory

CVE-2021-47737

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-23 19:35:47
Last updated 2026-04-07 14:05:51
Assigner VulnCheck
State PUBLISHED

Description

CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.