Impact
An authenticated user who can edit page content on GetSimple CMS CE can store a file path in the "template" attribute of a page. When that page is viewed, the CMS passes this path unsanitized to PHP’s include() function. Because the path can include directory traversal characters, an attacker can craft a page that causes the server to include any file on the filesystem, including files that contain PHP code. If such code is included, it is executed in the context of the web application, giving the attacker code‑execution privileges on the server. The vulnerability enables disclosure of sensitive files, modification of content, or full control of the affected system.
Affected Systems
GetSimple CMS Community Edition is affected in all releases 3.3.22 and older. The issue exists only for users with page‑editing rights and can be exploited on any HTTP front‑end that renders the page.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. EPSS data is not available, so the current estimated probability of exploitation is unknown but likely low to moderate. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session with page‑editing rights; an attacker who has compromised credentials or who can create a privileged user account can set the malicious template path and then trigger the inclusion by having any visitor load the affected page. Public disclosure is recent, so an immediate fix is preferable before a public exploit is discovered.
OpenCVE Enrichment