CVE-2021-42645: Malicious File Upload
CMSimpleXH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the "File" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42645?
CVE-2021-42645 is classified as a critical remote code execution vulnerability that can allow an attacker to gain control over the affected system.
How do I fix CVE-2021-42645?
The recommended fix for CVE-2021-42645 is to upgrade your CMSimple_XH installation to version 1.7.5 or later.
What versions are affected by CVE-2021-42645?
CVE-2021-42645 specifically affects CMSimple_XH version 1.7.4.
What kind of attack is facilitated by CVE-2021-42645?
CVE-2021-42645 facilitates remote code execution attacks through the 'File' parameter allowing the upload of malicious PHP payloads.
How can I detect if my CMSimple_XH installation is vulnerable to CVE-2021-42645?
You can detect vulnerability to CVE-2021-42645 by checking if your installation is running version 1.7.4 and testing for the ability to upload an arbitrary PHP file.