CVE-2021-47736

CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cmsimple-xh:cmsimple_xh:1.7.4:-:*:*:*:*:*:*

History

No history.

Information

Published : 2025-12-23 20:15

Updated : 2026-01-05 14:15


NVD link : CVE-2021-47736

Mitre link : CVE-2021-47736

CVE.ORG link : CVE-2021-47736


JSON object : View

Products Affected

cmsimple-xh

  • cmsimple_xh
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')