Junglewise Threat Intelligence

CVE-2021-47964: Schlix CMS remote code execution in block manager

CVE-2021-47964 · Severity: high · CVSS 8.8 · Published 2026-05-15

Executive brief

Schlix CMS, a platform used for building and managing websites, contains a security flaw that allows logged-in users to take full control of the web server. By uploading a specially crafted extension package, an attacker can run malicious commands on the underlying system. This could lead to the theft of sensitive data, website defacement, or a complete shutdown of the web service.

Technical details

A remote code execution (RCE) vulnerability exists in Schlix CMS versions up to 2.2.6-6 due to improper validation of uploaded extension packages. An authenticated attacker with access to the block manager ('/admin/app/core.blockmanager') can upload a crafted ZIP file containing malicious PHP code within the 'packageinfo.inc' file. The vulnerability is triggered when the administrator views the 'About' tab of the newly installed extension, causing the application to execute the embedded PHP code. This is classified as a code injection vulnerability (CWE-94). While the vendor has released newer versions (e.g., 2.2.9-5), users should ensure they are running a version where this specific vector is mitigated.

Affected products

  • Schlix Schlix CMS <= 2.2.6-6

Timeline

  • 2021-05-06: disclosed: Initial exploit published on Exploit-DB
  • 2026-05-15: advisory: NVD and VulnCheck published formal advisory details

References