PatchSiren cyber security CVE debrief
CVE-2021-47962 savsofts CVE debrief
A persistent cross-site scripting (XSS) vulnerability in Savsoft Quiz 5.0 allows authenticated attackers to inject malicious HTML and JavaScript code through user profile fields at the edit_user endpoint. The injected payloads execute in browsers of users viewing affected profiles. This vulnerability requires authentication and user interaction, limiting its exploitability but enabling session hijacking and credential theft against other users.
- Vendor
- savsofts
- Product
- Savsoft Quiz
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-05-18
Who should care
Organizations running Savsoft Quiz 5.0 for online assessments or training platforms. Security teams managing web application vulnerabilities and developers responsible for input validation in PHP-based quiz applications.
Technical summary
The vulnerability exists in the user account settings page of Savsoft Quiz 5.0, specifically at the edit_user endpoint. Authenticated users can submit malicious HTML and JavaScript payloads through profile fields without proper sanitization. These payloads are stored persistently and execute when other users view the affected profile. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N) reflects network accessibility, low complexity, required privileges, and user interaction, with impacts to system confidentiality and integrity.
Defensive priority
medium
Recommended defensive actions
- Apply input validation and output encoding for all user profile fields at the edit_user endpoint
- Implement Content Security Policy (CSP) headers to mitigate script execution
- Review and sanitize stored user data to remove existing malicious payloads
- Upgrade to a patched version when available from the vendor
- Monitor for suspicious profile modifications and script injection attempts
Evidence notes
Vulnerability disclosed via VulnCheck advisory with Exploit-DB reference. NVD status marked as 'Deferred'. CVSS 4.0 vector indicates network attack vector with low attack complexity, requiring privileges and user interaction.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-47962 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-47962
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-47962 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-47962
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/savsofts/savsoftquiz_v5
-
Source reference
Unverified legacy reference
URL: https://savsoftquiz.com/
-
Source reference
Unverified legacy reference
URL: https://www.exploit-db.com/exploits/49825
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/savsoft-quiz-persistent-cross-site-scripting-via-user-settings
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.