Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-47937— e107 CMS 2.3.0 Authenticated Remote Code Execution via Theme Upload

Quick assessment

Affected
E107 e107 CMS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

e107是E107团队的一套开源、免费且基于PHP和MySQL的内容管理系统(CMS)。该系统支持多种插件和外观主题,可作为个人博客、讨论社区、档案资料库等。 e107 2.3.0版本存在代码问题漏洞,该漏洞源于远程代码执行漏洞,允许具有主题安装权限的认证用户通过上传恶意主题文件执行任意命令,攻击者可以通过theme.php端点上传特制主题包,将Web shell部署到e107_themes目录,然后通过payload.php脚本执行系统命令。

CVSS 8.8 · High EPSS 0.59% · P46

Affected Version Matrix 1

VendorProduct Version RangeStatus
E107 e107 CMS 2.3.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-47937

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
e107 CMS 2.3.0 Authenticated Remote Code Execution via Theme Upload
Source: CVE Program / CVE List V5
Vulnerability Description
e107 CMS 2.3.0 contains a remote code execution vulnerability that allows authenticated users with theme installation permissions to execute arbitrary commands by uploading malicious theme files. Attackers can upload a crafted theme package through the theme.php endpoint that deploys a web shell to the e107_themes directory, then execute system commands via the payload.php script.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5
Vulnerability Title
e107 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
e107是E107团队的一套开源、免费且基于PHP和MySQL的内容管理系统(CMS)。该系统支持多种插件和外观主题,可作为个人博客、讨论社区、档案资料库等。 e107 2.3.0版本存在代码问题漏洞,该漏洞源于远程代码执行漏洞,允许具有主题安装权限的认证用户通过上传恶意主题文件执行任意命令,攻击者可以通过theme.php端点上传特制主题包,将Web shell部署到e107_themes目录,然后通过payload.php脚本执行系统命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
E107 e107 CMS 2.3.0 -

II. Public POCs for CVE-2021-47937

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-47937

请登录查看更多情报信息。

Vendor Advisories for CVE-2021-47937 (1)

Exploits & Public PoCs for CVE-2021-47937 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2021-47937

No comments yet


Leave a comment