CVE-2021-47981

Quick.CMS 6.7 contains a cross-site scripting vulnerability in the sliders form that allows authenticated attackers to inject malicious scripts by submitting XSS payloads through the sDescription parameter. Attackers can craft CSRF forms targeting the admin.php?p=sliders-form endpoint to execute arbitrary JavaScript in victim browsers when the form is submitted.
Configurations

No configuration.

History

No history.

Information

Published : 2026-05-16 16:16

Updated : 2026-06-17 04:18


NVD link : CVE-2021-47981

Mitre link : CVE-2021-47981

CVE.ORG link : CVE-2021-47981


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')