Vulnerability Description
CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cmsimple | Cmsimple | 5.4 |
Related Weaknesses (CWE)
References
- https://www.cmsimple.org/en/Product
- https://www.exploit-db.com/exploits/50547Exploit
- https://www.vulncheck.com/advisories/cmsimple-authenticated-local-file-inclusionThird Party Advisory
FAQ
What is CVE-2021-47734?
CVE-2021-47734 is a vulnerability with a CVSS score of 7.8 (HIGH). CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerabil...
How severe is CVE-2021-47734?
CVE-2021-47734 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47734?
Check the references section above for vendor advisories and patch information. Affected products include: Cmsimple Cmsimple.