Impact
GetSimple CMS Community Edition before version 1.5 lacked an anti‑CSRF token in the UpdateCE form and did not validate the request origin. A remote attacker can host a page that automatically submits a forged POST to the update endpoint. When an authenticated administrator visits that page, the server downloads and deploys the attacker’s chosen content within the administrator’s session, enabling arbitrary code execution. Additionally, the URL field is output unescaped, allowing an attacker to inject malicious markup via a crafted upgrade.json file. The combination of missing CSRF protection and unescaped output gives full remote code execution once an administrator interacts with the forged page.
Affected Systems
The vulnerability affects GetSimple CMS Community Edition, specifically all installations running a version earlier than 1.5. The patch that adds the missing CSRF token and input validation is included in the 1.5 release. No other vendor or product variants are listed.
Risk and Exploitability
The CVSS score of 9.6 classifies this as a critical flaw. Although no EPSS score is available, the absence of an EPSS rating does not reduce the seriousness of the flaw. The vulnerability is not listed in the CISA KEV catalog, but the lack of a CSRF token and unescaped URL field provide a straightforward attack path that requires only a contagious page presented to a logged‑in administrator. Successful exploitation would grant the attacker full remote code execution on the affected system.
OpenCVE Enrichment