CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.
History

Tue, 23 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.
Title CMSimple_XH 1.7.4 Authenticated Remote Code Execution via Content Editing
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-12-23T21:24:49.156Z

Reserved: 2025-12-23T13:24:04.579Z

Link: CVE-2021-47736

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-23T20:15:45.430

Modified: 2025-12-23T20:15:45.430

Link: CVE-2021-47736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.