Impact
An authenticated user that can edit a GetSimple CMS page can embed malicious JavaScript into the Keywords, Description, Menu text, or Content fields. When an administrator later opens the backup view for that page, the system decodes the previously HTML‑encoded fields and outputs them unescaped, causing the script to run in the admin control panel context. This stored cross‑site scripting allows the attacker to steal admin session cookies, deface the administration interface, or perform arbitrary actions as the administrator.
Affected Systems
The vulnerability affects GetSimple CMS Community Edition, versions 3.3.22 and earlier, where the backup viewer (admin/backup-edit.php) decodes page data during display. The affected product is GetSimpleCMS‑CE; no further vendor or product details are specified in the advisory.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker must first be authenticated with permission to edit a page and then rely on an administrator to open the backup edit page. Because the attack occurs when an admin views the backup, the exploitation window is limited to periods when admins are actively using the control panel, but the risk is significant due to the potential for credential theft and lateral movement.
OpenCVE Enrichment