CVE-2021-47734

CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cmsimple:cmsimple:5.4:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-23 20:15

Updated : 2026-01-05 14:15


NVD link : CVE-2021-47734

Mitre link : CVE-2021-47734

CVE.ORG link : CVE-2021-47734


JSON object : View

Products Affected

cmsimple

  • cmsimple
CWE
CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')