Vendorsget-simplegetsimple_cms3.3.13
Vulnerabilities

get-simple GetSimple CMS 3.3.13

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-17103
An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter
Published 2018-09-16 · Modified
8.8EPSS 0.007
CVE-2018-9173
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.
Published 2018-04-02 · Modified
6.11 PoCEPSS 0.024