Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
GetSimple CMS Custom JS 0.1 - CSRF to XSS to RCE
Vulnerability Description
GetSimple CMS Custom JS 0.1 plugin contains a cross-site request forgery vulnerability that allows unauthenticated attackers to inject arbitrary client-side code into administrator browsers. Attackers can craft a malicious website that triggers a cross-site scripting payload to execute remote code on the hosting server when an authenticated administrator visits the page.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
GetSimple Content Management System 跨站请求伪造漏洞
Vulnerability Description
GetSimple Content Management System是GetSimpleCMS开源的一个内容管理系统。 GetSimple Content Management System存在跨站请求伪造漏洞,该漏洞源于存在跨站请求伪造,可能导致在管理员浏览器中执行任意客户端代码。
CVSS Information
N/A
Vulnerability Type
N/A