CVE-2021-28976: Malicious File Upload
Published Jun 23, 2021
·Updated
Remote Code Execution vulnerability in GetSimpleCMS before 3.3.16 in admin/upload.php via phar filess.
Affected Software
1 affected component
Get-simple Getsimplecms<3.3.15
Event History
Jun 23, 2021
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
Description
Apr 11, 2025
Exploit Published
12:00 AM
Known Exploited
05:48 AM
Frequently Asked Questions
1
What is CVE-2021-28976?
CVE-2021-28976 is a remote code execution vulnerability in GetSimpleCMS before version 3.3.16 in the admin/upload.php file via phar files.
2
What is the severity of CVE-2021-28976?
CVE-2021-28976 has a severity rating of 7.2, which is considered high.
3
How does CVE-2021-28976 affect GetSimpleCMS?
CVE-2021-28976 affects GetSimpleCMS versions up to and excluding 3.3.16.
4
How can I fix CVE-2021-28976?
To fix CVE-2021-28976, you need to update GetSimpleCMS to version 3.3.16 or later.
5
Where can I find more information about CVE-2021-28976?
More information about CVE-2021-28976 can be found at the following link: [CVE-2021-28976](https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1335)