Vulnerability Description
Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters in the admin.php file to compromise the database management system and web application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simplephpscripts | Simple Cms Php | 2.1 |
Related Weaknesses (CWE)
References
- https://simplephpscripts.com/simple-cms-phpProduct
- https://www.vulncheck.com/advisories/simple-cms-sql-injection-vulnerability-via-Broken Link
- https://www.vulnerability-lab.com/get_content.php?id=2303ExploitThird Party Advisory
FAQ
What is CVE-2021-47918?
CVE-2021-47918 is a vulnerability with a CVSS score of 8.1 (HIGH). Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidated input parameters ...
How severe is CVE-2021-47918?
CVE-2021-47918 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-47918?
Check the references section above for vendor advisories and patch information. Affected products include: Simplephpscripts Simple Cms Php.