PT-2026-3030 · Phpkf Cms · Phpkf Cms

Halit Akaydin

·

Published

2026-01-15

·

Updated

2026-01-20

·

CVE-2021-47753

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions phpKF CMS version 3.00 Beta y6
Description The software contains an unauthenticated file upload issue that enables remote attackers to execute arbitrary code. This is achieved by bypassing file extension checks, allowing attackers to upload a PHP file disguised as a PNG. After uploading, the file can be renamed and used to execute system commands through a crafted web shell parameter.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2021-47753

Affected Products

Phpkf Cms