CMSimple 5.4 Authenticated Local File Inclusion Remote Code Execution
Vulnerability Description
CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-47734
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- S1lv3r
References
Affected Vendor
Cmsimple
View all reports →