Beveiligingsadvies

CVE-2021-47937

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-05-10 12:43:55
Laatst bijgewerkt 2026-05-12 02:38:57
Toegewezen door VulnCheck
CVSS-score 8.8
Status PUBLISHED

Beschrijving

e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that deploys a web shell to the e107_themes directory, then execute system commands via the payload.php script.