Impact
This vulnerability occurs in the update handler of GetSimple CMS CE prior to version 1.5. An attacker who can submit the update form can supply any URL; the server fetches that URL using file_get_contents without validating the destination. The response is written to a temporary file that remains on the web root, allowing the attacker to read the content of any internal service or cloud metadata endpoint. The flaw enables SSRF with read access, potentially exposing sensitive internal data.
Affected Systems
GetSimple CMS CE versions earlier than 1.5. The vulnerability affects all installations of GetSimple CMS Community Edition that have the update feature enabled and allow users to submit URLs to the update handler.
Risk and Exploitability
The vulnerability scores 7.5 on CVSS. The EPSS score is not available, and it is not listed in the CISA KEV catalog. An attacker would need the ability to submit the update form, which may require authenticated access to the CMS admin interface. Once the request is submitted, the server will contact arbitrary URLs, including internal-only services and cloud metadata endpoints such as 169.254.169.254, and the response content is returned to the attacker via the web‑accessible temporary file. The lack of validation and file deletion turns this into a full‑read SSRF that can be exploited to read internal secrets or sensitive data.
OpenCVE Enrichment