VYPR
Medium severity5.4NVD Advisory· Published Dec 23, 2025· Updated Jun 17, 2026

CVE-2021-47737

CVE-2021-47737

Description

CSZ CMS 1.2.7 contains an HTML injection vulnerability that allows authenticated users to insert malicious hyperlinks in message titles. Attackers can craft POST requests to the member messaging system with HTML-based links to potentially conduct phishing or social engineering attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • CSZ CMS/cszcmsllm-fuzzy3 versions
    <1.2.7+ 2 more
    • (no CPE)range: <1.2.7
    • cpe:2.3:a:cszcms:csz_cms:1.2.7:*:*:*:*:*:*:*
    • (no CPE)range: 1.2.7

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.