PT-2026-5562 · Unknown · Simple-Cms

Published

2026-02-01

·

Updated

2026-02-01

·

CVE-2021-47917

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Simple CMS version 2.1
Description Simple CMS version 2.1 contains a persistent cross-site scripting issue in user input parameters. Remote attackers can inject malicious script code through the newUser and editUser modules. Successful exploitation allows the injection of persistent scripts that execute on the user list preview, potentially leading to session hijacking and application manipulation.
Recommendations Update Simple CMS to a newer version that addresses this issue. As a temporary workaround, consider restricting or disabling the newUser and editUser modules until a patch is available.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-47917

Affected Products

Simple-Cms