nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47734 CVE-2021-47734
HIGH
CMSimple 5.4 Authenticated Local File Inclusion Remote Code Execution
Record summary
CVE-2021-47734 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 17, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CMSimpleBrowse Cmsimple / CMSimple | CVE List | CMSimple 5.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCMSimple 5.4 - Local file inclusion (LFI) to Remote code execution (RCE) (Authenticated)ExploitDB exploitby S1lv3rNot analyzed1 file
References
4Official CMSimple Homepageproduct
https://www.cmsimple.org/en ExploitDB-50547exploit
https://www.exploit-db.com/exploits/50547 VulnCheck Advisory: CMSimple 5.4 Authenticated Local File Inclusion Remote Code ExecutionThird-party advisory
https://www.vulncheck.com/advisories/cmsimple-authenticated-local-file-inclusion-remote-code-execution