CVE-2021-47735: CMSimple 5.4 Authenticated Remote Code Execution via Template Editing
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47735?
CVE-2021-47735 has a high severity rating due to its potential for authenticated remote code execution.
How do I fix CVE-2021-47735?
To fix CVE-2021-47735, you should update CMSimple to the latest version that addresses this vulnerability.
What type of attack does CVE-2021-47735 allow?
CVE-2021-47735 allows authenticated attackers to perform remote code execution by injecting malicious PHP code.
Who is affected by CVE-2021-47735?
CMSimple versions prior to 5.4 are affected by CVE-2021-47735.
What can attackers do with CVE-2021-47735?
Attackers can exploit CVE-2021-47735 to craft a reverse shell payload and execute arbitrary code on the server.