Stored XSS Vulnerability in BlackCat CMS Admin Panel
CVE-2021-27237
4.8MEDIUM
What is CVE-2021-27237?
The admin panel of BlackCat CMS version 1.3.6 is susceptible to a stored XSS vulnerability. This flaw allows malicious code to be injected through the Display Name field, ultimately affecting the backend preferences via ajax_save.php. If exploited, an attacker could execute scripts in the context of the user's session, potentially compromising sensitive data or performing unauthorized actions.
