PT-2026-103991 · Unknown · Getsimple Cms
CVE-2026-56662
·
Published
2026-10-01
·
Updated
2026-10-02
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GetSimple CMS versions prior to 1.5
Description
The UpdateCE update form lacks anti-CSRF tokens, and the POST handler does not verify tokens or request origins. This allows a remote attacker to host a page that auto-submits a forged POST request to the update endpoint. If an authenticated administrator visits this page, the server performs a download-and-deploy operation within the administrator's session without further interaction. Since the deployed content is executed, this leads to remote code execution. Additionally, the
url field is written into the form without escaping, creating an HTML-injection sink via a malicious upgrade.json file.Recommendations
Update to version 1.5.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getsimple Cms