Логотип exploitDog
bind:CVE-2021-47736
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-47736

Количество 2

Количество 2

nvd логотип

CVE-2021-47736

около 2 месяцев назад

CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-353h-pmfp-h8fp

около 2 месяцев назад

CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-47736

CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.

CVSS3: 7.2
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-353h-pmfp-h8fp

CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.

CVSS3: 8.8
1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу