{"id":"CVE-2021-42645","details":"CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker must use the \"File\" parameter to upload a PHP payload to get a reverse shell from the vulnerable host.","modified":"2026-05-15T12:04:21.317365569Z","published":"2022-05-10T12:15:08.477Z","database_specific":{},"references":[{"type":"ADVISORY","url":"https://github.com/cmsimple-xh/cmsimple-xh/releases/tag/1.7.5"},{"type":"EVIDENCE","url":"https://github.com/Net-hunter121/CMSimple_XH-Unauth-RCE"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}