CVE-2021-47735 Details
Description
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse shell payload and saving it through the template editing endpoint with a valid CSRF token.
A remote code execution vulnerability has been identified in CMSimple version 5.4. This vulnerability allows authenticated attackers to inject malicious PHP code into template files. Exploitation involves using the template editing feature to save a crafted payload, such as a reverse shell, through the template editing endpoint, accompanied by a valid CSRF token.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cmsimple.org/ | [email protected] | Product |
| https://www.exploit-db.com/exploits/50356 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/cmsimple-authenticated-remote-code-execution-via-template-editing | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cmsimple cmsimple | 5.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 31, 2025 | Initial Analysis | [email protected] |
| Dec 23, 2025 | New CVE Received | [email protected] |