PT-2026-103991 · Unknown · Getsimple Cms

CVE-2026-56662

·

Published

2026-10-01

·

Updated

2026-10-02

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GetSimple CMS versions prior to 1.5
Description The UpdateCE update form lacks anti-CSRF tokens, and the POST handler does not verify tokens or request origins. This allows a remote attacker to host a page that auto-submits a forged POST request to the update endpoint. If an authenticated administrator visits this page, the server performs a download-and-deploy operation within the administrator's session without further interaction. Since the deployed content is executed, this leads to remote code execution. Additionally, the url field is written into the form without escaping, creating an HTML-injection sink via a malicious upgrade.json file.
Recommendations Update to version 1.5.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56662

Affected Products

Getsimple Cms