C
MSimple 5.4 contains an authenticated local file inclusion vulnerability that allows remote attackers to manipulate PHP session files and execute arbitrary code. Attackers can leverage the vulnerability by changing the functions file path and uploading malicious PHP code through session file upload mechanisms.
References
| Link | Resource |
|---|---|
| https://www.cmsimple.org/en/ | Product |
| https://www.exploit-db.com/exploits/50547 | Exploit |
| https://www.vulncheck.com/advisories/cmsimple-authenticated-local-file-inclusion-remote-code-execution | Third Party Advisory |
Configurations
History
05 Jan 2026, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
31 Dec 2025, 21:43
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Cmsimple
Cmsimple cmsimple |
|
| CPE | cpe:2.3:a:cmsimple:cmsimple:5.4:*:*:*:*:*:*:* | |
| References | () https://www.cmsimple.org/en/ - Product | |
| References | () https://www.exploit-db.com/exploits/50547 - Exploit | |
| References | () https://www.vulncheck.com/advisories/cmsimple-authenticated-local-file-inclusion-remote-code-execution - Third Party Advisory |
23 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-23 20:15
Updated : 2026-01-05 14:15
NVD link : CVE-2021-47734
Mitre link : CVE-2021-47734
CVE.ORG link : CVE-2021-47734
JSON object : View
CWE
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')