Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.
Published: 2026-10-01
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

GetSimple CMS Community Edition before version 1.5 lacked an anti‑CSRF token in the UpdateCE form and did not validate the request origin. A remote attacker can host a page that automatically submits a forged POST to the update endpoint. When an authenticated administrator visits that page, the server downloads and deploys the attacker’s chosen content within the administrator’s session, enabling arbitrary code execution. Additionally, the URL field is output unescaped, allowing an attacker to inject malicious markup via a crafted upgrade.json file. The combination of missing CSRF protection and unescaped output gives full remote code execution once an administrator interacts with the forged page.

Affected Systems

The vulnerability affects GetSimple CMS Community Edition, specifically all installations running a version earlier than 1.5. The patch that adds the missing CSRF token and input validation is included in the 1.5 release. No other vendor or product variants are listed.

Risk and Exploitability

The CVSS score of 9.6 classifies this as a critical flaw. Although no EPSS score is available, the absence of an EPSS rating does not reduce the seriousness of the flaw. The vulnerability is not listed in the CISA KEV catalog, but the lack of a CSRF token and unescaped URL field provide a straightforward attack path that requires only a contagious page presented to a logged‑in administrator. Successful exploitation would grant the attacker full remote code execution on the affected system.

Generated by OpenCVE AI on October 1, 2026 at 20:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GetSimple CMS Community Edition to version 1.5 or later, which implements anti‑CSRF tokens in the UpdateCE endpoint.
  • Ensure administrators use strong, unique passwords and enable two‑factor authentication to reduce the likelihood that a compromised login can be used for exploitation.
  • Surveil the update endpoint for any requests lacking a valid CSRF token or originating from unexpected origins, and block such requests to prevent unauthorized deployment actions.

Generated by OpenCVE AI on October 1, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.
Title GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-01T19:38:30.623Z

Reserved: 2026-06-22T16:39:01.043Z

Link: CVE-2026-56662

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T20:17:26.950

Modified: 2026-10-01T20:23:46.493

Link: CVE-2026-56662

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:30:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)