CMSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.
References
| Link | Resource |
|---|---|
| https://www.cmsimple.org/en/ | Product |
| https://www.exploit-db.com/exploits/50547 | Exploit |
| https://www.vulncheck.com/advisories/cmsimple-authenticated-local-file-inclusion-remote-code-execution | Third Party Advisory |
Configurations
History
05 Jan 2026, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
31 Dec 2025, 21:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.cmsimple.org/en/ - Product | |
| References | () https://www.exploit-db.com/exploits/50547 - Exploit | |
| References | () https://www.vulncheck.com/advisories/cmsimple-authenticated-local-file-inclusion-remote-code-execution - Third Party Advisory | |
| First Time |
Cmsimple
Cmsimple cmsimple |
|
| CPE | cpe:2.3:a:cmsimple:cmsimple:5.4:*:*:*:*:*:*:* |
23 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-23 20:15
Updated : 2026-01-05 14:15
NVD link : CVE-2021-47734
Mitre link : CVE-2021-47734
CVE.ORG link : CVE-2021-47734
JSON object : View
Products Affected
cmsimple
- cmsimple
CWE
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
