CVE-2021-47778: GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection
GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code through plugin configuration parameters, leading to remote code execution on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GetSimple CMS My SMTP Contact Pluginto a version that resolves this vulnerability.Fixed in 1.1.2Patch GetSimple CMS My SMTP Contact Plugin 1.1.2 - PHP Code Injection
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47778?
CVE-2021-47778 is considered a high severity vulnerability due to its ability to allow remote code execution.
How do I fix CVE-2021-47778?
To fix CVE-2021-47778, update to the latest version of the GetSimple CMS My SMTP Contact Plugin that addresses this vulnerability.
Who is affected by CVE-2021-47778?
CVE-2021-47778 affects all installations of GetSimple CMS My SMTP Contact Plugin version 1.1.2.
What type of vulnerability is CVE-2021-47778?
CVE-2021-47778 is a PHP code injection vulnerability allowing unauthorized execution of arbitrary PHP code.
What might an attacker be able to achieve with CVE-2021-47778?
An attacker exploiting CVE-2021-47778 could potentially execute arbitrary code on the server, leading to full system compromise.