CVE-2021-47939 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: May 10, 2026
Evolution CMS - Remote Code Execution
Published: May 10, 2026Updated: May 10, 2026Remote Exploitable
Overview
Evolution CMS 3.1.6 contains a remote code execution caused by PHP code injection in module parameters via POST requests to /manager/index.php, letting authenticated users with module creation permissions execute arbitrary system commands.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Authenticated users with module creation permissions can execute arbitrary system commands, potentially leading to full system compromise.
Mitigation
Update to the latest version of Evolution CMS.
References
Related Resources
Details
- CVE ID
- CVE-2021-47939
- Severity
- High
- CVSS Score
- 8.8
- Type
- command_injection
- Status
- new
CWE
- CWE-94
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H