Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches.
Published: 2026-10-01
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Administrator Account Takeover
Action: Seek Patch
AI Analysis

Impact

GetSimple CMS CE exposes a password reset function that can be invoked without authentication. The reset endpoint generates a new temporary password using PHP rand() seeded with microtime(). Because the seed is time‑based and has a very small search space, an attacker can enumerate likely passwords offline. The generated password is immediately stored hashed as the user’s password, allowing an attacker to try candidate passwords online until the correct one is found. Successful exploitation results in the attacker gaining administrative access to the CMS.

Affected Systems

The flaw affects GetSimple CMS Community Edition 3.3.22. No other versions are listed as vulnerable in the advisory. Users running 3.3.22 should assume the vulnerability is present.

Risk and Exploitability

The CVSS score of 9.1 indicates high severity. No EPSS score was reported, but the lack of rate limiting or account lockout means brute‑force attempts can be conducted in realtime. The vulnerability is not listed in the CISA KEV catalog at this time, but the remote nature of the attack and the ability to quickly discover a valid admin password make it a high‑risk exposure for any publicly accessible deployment.

Generated by OpenCVE AI on October 1, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update GetSimple CMS CE to a patched version once it becomes available
  • Disable the password reset endpoint or block it via the web server to prevent unauthorized reset requests
  • Implement rate limiting or an account lockout policy on the admin login to mitigate brute‑force attempts

Generated by OpenCVE AI on October 1, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches.
Title GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover
Weaknesses CWE-338
CWE-640
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:36:17.930Z

Reserved: 2026-06-11T15:50:01.281Z

Link: CVE-2026-53953

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:25.283

Modified: 2026-10-01T20:25:35.640

Link: CVE-2026-53953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:30:04Z

Weaknesses
  • CWE-338

    Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password