关键漏洞信息 漏洞名称: Textpattern 4.8.3 - Remote code execution 严重性: High 日期: January 22, 2026 影响版本: Textpattern 4.8.3 CVE编号: CVE-2021-47888 漏洞类型: CWE-434 Unrestricted Upload of File with Dangerous Type CVSS评分: 9.8/CVSS:3.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N 参考资料: - ExploitDB-49620 - Official Vendor Homepage - Textpattern Software Download Page 发现者: Ricardo Ruiz (@ricardojoserf) 描述: Textpattern versions prior to 4.8.3 contain an authenticated remote code execution vulnerability that allows logged-in users to upload malicious PHP files. Attackers can upload a PHP file with a shell command execution payload and execute arbitrary commands by accessing the uploaded file through a specific URL parameter.