Impact
The vulnerability stems from a logic flaw in the automated deletion routine that is meant to remove a sensitive script after installation. The flaw neutralizes the removal process, leaving the setup script in the web root. Because the script remains accessible, an attacker can create a fully privileged administrator account without needing prior authentication, granting unrestricted access to content management, configuration, and potential code execution. The issue exists in GetSimple CMS and its community edition.
Affected Systems
GetSimpleCMS-CE versions 3.3.22 and earlier, and GetSimpleCMS versions 3.4.0a and earlier, are impacted. No patched releases have been issued at the time of this advisory.
Risk and Exploitability
The CVSS score of 9.8 marks this as a critical vulnerability. The EPSS score of less than 1% indicates a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit it simply by accessing the exposed setup script, creating an administrator account, and thereafter performing any action allowed by that role. The impact spans confidentiality, integrity, and availability of the CMS system.
OpenCVE Enrichment