vendor:
GetSimple CMS
by:
10n1z3d
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
352 (Cross-Site Request Forgery (CSRF)) and 79 (Cross-Site Scripting (XSS))
CWE
Product Name: GetSimple CMS
Affected Version From: 2.01
Affected Version To: 2.01
Patch Exists: NO
Related CWE: N/A
CPE: a:get-simple:get-simple_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010
GetSimple CMS 2.01 Multiple Vulnerabilities (XSS/CSRF)
GetSimple CMS 2.01 is vulnerable to Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS). An attacker can exploit these vulnerabilities to change the admin password, delete pages, delete all backups, and logout the administrator. Additionally, more vulnerabilities can be found in the admin panel.
Mitigation:
Implementing a strong CSRF protection mechanism and validating user input to prevent XSS attacks.