CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server. | |
| Title | CMSimple_XH 1.7.4 Authenticated Remote Code Execution via Content Editing | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-23T21:24:49.156Z
Reserved: 2025-12-23T13:24:04.579Z
Link: CVE-2021-47736
No data.
Status : Received
Published: 2025-12-23T20:15:45.430
Modified: 2025-12-23T20:15:45.430
Link: CVE-2021-47736
No data.
OpenCVE Enrichment
No data.