CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.
History

Wed, 24 Dec 2025 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Cmsimple-xh
Cmsimple-xh cmsimple Xh
Vendors & Products Cmsimple-xh
Cmsimple-xh cmsimple Xh

Tue, 23 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 23 Dec 2025 19:45:00 +0000

Type Values Removed Values Added
Description CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF token mechanism to create a PHP shell file that enables arbitrary command execution on the server.
Title CMSimple_XH 1.7.4 Authenticated Remote Code Execution via Content Editing
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-12-23T19:34:09.538Z

Updated: 2025-12-23T21:24:49.156Z

Reserved: 2025-12-23T13:24:04.579Z

Link: CVE-2021-47736

cve-icon Vulnrichment

Updated: 2025-12-23T21:24:45.461Z

cve-icon NVD

Status : Received

Published: 2025-12-23T20:15:45.430

Modified: 2025-12-23T20:15:45.430

Link: CVE-2021-47736

cve-icon Redhat

No data.