Security Advisory

CVE-2021-47937

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-10 12:43:55
Last updated 2026-05-12 02:38:57
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that deploys a web shell to the e107_themes directory, then execute system commands via the payload.php script.