PT-2026-41343 · Schlix · Schlix Cms

Eren Saraç

·

Published

2026-05-15

·

Updated

2026-05-15

·

CVE-2021-47964

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP file containing PHP code in the packageinfo.inc file and trigger execution by accessing the About tab of the installed extension.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-47964

Affected Products

Schlix Cms