Impact
The vulnerability in GetSimple CMS Community Edition allows an attacker to cause a malicious ZIP archive to be downloaded and extracted by the update handler. The extraction process writes PHP files directly into a web‑accessible directory without validating file types or the extraction path. Directory traversal is also possible because entry names are used unsafely, enabling files to be written outside the intended location. If an attacker can supply or force the processing of such an archive, they can execute arbitrary code on the server as the web‑server user, potentially compromising the entire site.
Affected Systems
GetSimple CMS Community Edition before version 1.5 is affected. The update handler in UpdateCE.php is the entry point for the exploit. Users running any pre‑1.5 instance of the CMS are at risk, regardless of other configuration, because the vulnerability exists purely in the core update functionality.
Risk and Exploitability
Risk is high. The CVSS score of 9.1 underscores the potential for full control. The EPSS score is not available, but the known attack paths—CSRF, SSRF, or forced update—make exploitation likely if an attacker can trigger the update handler. The vulnerability is not in the KEV catalog, but that does not diminish the critical nature of the flaw.
OpenCVE Enrichment