PT-2026-3156 · Phpcms · Phpcms
Okan Kurtulus
·
Published
2026-01-15
·
Updated
2026-02-09
·
CVE-2021-47783
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Phpwcms version 1.9.30
Description
The software contains a file upload issue that permits authenticated attackers to upload malicious SVG files containing JavaScript. Attackers can leverage the multiple file upload functionality to upload specially crafted SVG payloads, potentially leading to cross-site scripting attacks on the platform. The vulnerable functionality involves the upload of files.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpcms