Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-02-01 13:15
Updated : 2026-02-03 16:44
NVD link : CVE-2021-47918
Mitre link : CVE-2021-47918
CVE.ORG link : CVE-2021-47918
JSON object : View
Products Affected
No product.
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
