CVE-2021-47937 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: May 10, 2026
e107 CMS - Remote Code Execution
Published: May 10, 2026Updated: May 10, 2026Remote Exploitable
Overview
e107 CMS 2.3.0 contains a remote code execution caused by improper validation of uploaded theme files in theme.php, letting authenticated users with theme installation permissions execute arbitrary commands.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Authenticated users with theme installation permissions can execute arbitrary system commands, potentially leading to full server compromise.
Mitigation
Update to the latest version of e107 CMS.
References
Related Resources
Details
- CVE ID
- CVE-2021-47937
- Severity
- High
- CVSS Score
- 8.8
- Type
- command_injection
- Status
- new
CWE
- CWE-434
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H