Skip to content
CVE-2021-47939 - Exploits & Severity

CVE-2021-47939 - Exploits & Severity

Feedly May 10, 2026

Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST requests to /manager/index.php with malicious PHP code in the 'post' parameter to create modules that execute arbitrary commands when invoked.

An authenticated user with module creation permissions can send POST requests to /manager/index.php with malicious PHP code to create modules that execute arbitrary system commands.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

No patch information available in provided data

Restrict module creation permissions to trusted administrators only. Implement input validation and sanitization for all module parameters. Monitor /manager/index.php for suspicious POST requests containing PHP code. Consider disabling PHP code execution within module parameters if not required for legitimate functionality.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

NVD published the first details for CVE-2021-47939

A CVSS base score of 8.8 has been assigned.

Feedly found the first article mentioning CVE-2021-47939 . See article

GitHub Advisories released a security advisory .

CVE Alert: CVE-2021-47939 - Evo - Evolution CMS - RedPacket Security

CVE-2021-47939 | Evolution CMS 3.1.6 /manager/index.php post code injection (Exploit 50296 / EDB-50296)

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities