BloofoxCMS 0.5.2.1 contains a stored cross-site scripting vulnerability in the articles text parameter that allows authenticated attackers to inject malicious scripts. Attackers can insert malicious javascript payloads in the text field to execute scripts and potentially steal authenticated users' cookies.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-23 17:16
Updated : 2026-01-26 15:03
NVD link : CVE-2021-47906
Mitre link : CVE-2021-47906
CVE.ORG link : CVE-2021-47906
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
