Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5.
Published: 2026-10-01
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in GetSimple CMS Community Edition allows an attacker to cause a malicious ZIP archive to be downloaded and extracted by the update handler. The extraction process writes PHP files directly into a web‑accessible directory without validating file types or the extraction path. Directory traversal is also possible because entry names are used unsafely, enabling files to be written outside the intended location. If an attacker can supply or force the processing of such an archive, they can execute arbitrary code on the server as the web‑server user, potentially compromising the entire site.

Affected Systems

GetSimple CMS Community Edition before version 1.5 is affected. The update handler in UpdateCE.php is the entry point for the exploit. Users running any pre‑1.5 instance of the CMS are at risk, regardless of other configuration, because the vulnerability exists purely in the core update functionality.

Risk and Exploitability

Risk is high. The CVSS score of 9.1 underscores the potential for full control. The EPSS score is not available, but the known attack paths—CSRF, SSRF, or forced update—make exploitation likely if an attacker can trigger the update handler. The vulnerability is not in the KEV catalog, but that does not diminish the critical nature of the flaw.

Generated by OpenCVE AI on October 1, 2026 at 20:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch that brings the CMS to version 1.5 or later
  • If patching is not immediately possible, disable or restrict the update handler in UpdateCE.php by removing its execution rights or moving the file out of the web root
  • Validate uploaded or extracted file types and reject any ZIP entries that contain PHP or binary code, and sanitize extraction paths to prevent directory traversal

Generated by OpenCVE AI on October 1, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5.
Title GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
Weaknesses CWE-352
CWE-434
CWE-918
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:54:11.631Z

Reserved: 2026-06-22T16:39:01.043Z

Link: CVE-2026-56660

cve-icon Vulnrichment

Updated: 2026-10-01T19:53:35.242Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:26.643

Modified: 2026-10-01T20:23:46.493

Link: CVE-2026-56660

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:30:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-434

    Unrestricted Upload of File with Dangerous Type

  • CWE-918

    Server-Side Request Forgery (SSRF)