Impact
GetSimple CMS CE exposes a password reset function that can be invoked without authentication. The reset endpoint generates a new temporary password using PHP rand() seeded with microtime(). Because the seed is time‑based and has a very small search space, an attacker can enumerate likely passwords offline. The generated password is immediately stored hashed as the user’s password, allowing an attacker to try candidate passwords online until the correct one is found. Successful exploitation results in the attacker gaining administrative access to the CMS.
Affected Systems
The flaw affects GetSimple CMS Community Edition 3.3.22. No other versions are listed as vulnerable in the advisory. Users running 3.3.22 should assume the vulnerability is present.
Risk and Exploitability
The CVSS score of 9.1 indicates high severity. No EPSS score was reported, but the lack of rate limiting or account lockout means brute‑force attempts can be conducted in realtime. The vulnerability is not listed in the CISA KEV catalog at this time, but the remote nature of the attack and the ability to quickly discover a valid admin password make it a high‑risk exposure for any publicly accessible deployment.
OpenCVE Enrichment