Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Remote Server Side Request Forgery
Action: Immediate Patch
AI Analysis

Impact

This vulnerability occurs in the update handler of GetSimple CMS CE prior to version 1.5. An attacker who can submit the update form can supply any URL; the server fetches that URL using file_get_contents without validating the destination. The response is written to a temporary file that remains on the web root, allowing the attacker to read the content of any internal service or cloud metadata endpoint. The flaw enables SSRF with read access, potentially exposing sensitive internal data.

Affected Systems

GetSimple CMS CE versions earlier than 1.5. The vulnerability affects all installations of GetSimple CMS Community Edition that have the update feature enabled and allow users to submit URLs to the update handler.

Risk and Exploitability

The vulnerability scores 7.5 on CVSS. The EPSS score is not available, and it is not listed in the CISA KEV catalog. An attacker would need the ability to submit the update form, which may require authenticated access to the CMS admin interface. Once the request is submitted, the server will contact arbitrary URLs, including internal-only services and cloud metadata endpoints such as 169.254.169.254, and the response content is returned to the attacker via the web‑accessible temporary file. The lack of validation and file deletion turns this into a full‑read SSRF that can be exploited to read internal secrets or sensitive data.

Generated by OpenCVE AI on October 1, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GetSimple CMS CE to version 1.5 or later, which removes the insecure file_get_contents call in the update handler.
  • If upgrading immediately is not possible, disable the update endpoint or restrict it to trusted administrators to prevent unauthorized form submissions.
  • Configure network rules or use firewalls to block unexpected outbound traffic from the web server, especially to internal IP ranges and the 169.254.169.254 metadata service.

Generated by OpenCVE AI on October 1, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.
Title GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:50:54.335Z

Reserved: 2026-06-22T16:39:01.043Z

Link: CVE-2026-56661

cve-icon Vulnrichment

Updated: 2026-10-01T19:50:50.630Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:26.793

Modified: 2026-10-01T20:23:46.493

Link: CVE-2026-56661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:30:04Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)