CVE-2021-47734: CMSimple 5.4 Authenticated Local File Inclusion Remote Code Execution
CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47734?
CVE-2021-47734 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2021-47734?
To fix CVE-2021-47734, upgrade to the latest version of CMSimple that includes a patch for this vulnerability.
Can CVE-2021-47734 be exploited without authentication?
No, CVE-2021-47734 requires authenticated access to exploit the local file inclusion vulnerability.
What types of attacks can CVE-2021-47734 enable?
CVE-2021-47734 can enable attackers to manipulate PHP session files and execute arbitrary code on the server.
Which versions of CMSimple are affected by CVE-2021-47734?
CVE-2021-47734 affects CMSimple version 5.4.