CVE-2021-47937: e107 CMS 2.3.0 Authenticated Remote Code Execution via Theme Upload
e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that deploys a web shell to the e107themes directory, then execute system commands via the payload.php script.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47937?
CVE-2021-47937 is classified as a critical remote code execution vulnerability.
How do I fix CVE-2021-47937?
To fix CVE-2021-47937, upgrade e107 CMS to version 2.3.1 or later, where the vulnerability is patched.
Who is affected by CVE-2021-47937?
CVE-2021-47937 affects users of e107 CMS version 2.3.0 who have theme installation permissions.
What can an attacker do with CVE-2021-47937?
An attacker can exploit CVE-2021-47937 to execute arbitrary commands on the server by uploading malicious theme files.
How does CVE-2021-47937 impact e107 CMS security?
CVE-2021-47937 significantly compromises the security of e107 CMS, allowing unauthorized remote code execution.