VYPR
Medium severity6.1NVD Advisory· Published Dec 31, 2025· Updated Apr 15, 2026

CVE-2021-47743

CVE-2021-47743

Description

COMMAX Biometric Access Control System 1.0.0 contains an unauthenticated reflected cross-site scripting vulnerability in cookie parameters 'CMX_ADMIN_NM' and 'CMX_COMPLEX_NM'. Attackers can inject malicious HTML and JavaScript code into these cookie values to execute arbitrary scripts in a victim's browser session.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

COMMAX Biometric Access Control System 1.0.0 is vulnerable to unauthenticated reflected XSS via cookie parameters CMX_ADMIN_NM and CMX_COMPLEX_NM.

The COMMAX Biometric Access Control System version 1.0.0 contains an unauthenticated reflected cross-site scripting (XSS) vulnerability in the cookie parameters CMX_ADMIN_NM and CMX_COMPLEX_NM. Input passed to these cookies is not properly sanitized before being reflected back to the user, allowing injection of arbitrary HTML and JavaScript code.[2][3]

An attacker can exploit this by crafting malicious cookie values and enticing a victim to visit a page on the affected system where the cookies are reflected—for example, /db_dump.php as shown in the proof-of-concept.[3] The attack does not require authentication and can be executed simply by luring the victim to a specially crafted link or using social engineering to set the cookies.

Successful exploitation enables arbitrary script execution in the victim's browser within the context of the affected site. This can lead to session hijacking, defacement, or redirection to malicious content. The vulnerability was disclosed by Gjoko 'LiquidWorm' Krstic via Zero Science Lab.[2][4]

As of the latest publication, no official patch has been released. The vendor has not provided a fix, so organizations using this system should restrict access to the web interface, apply proper input validation, and monitor for suspicious activity. The CVE is not currently listed on the CISA KEV catalog.[1][4]

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.