GetSimple CMS 是一种内容管理系统(CMS),而 GetSimple CMS CE 是该 CMS 的社区版。GetSimple CMS(v3.4.0a 及以下版本)和 GetSimpleCMS-CE(v3.3.22 及以下版本)中存在一个逻辑缺陷,使得未经身份验证的攻击者能够创建新的管理员账户。 该应用程序具备一项自动化安全控制机制,旨在在安装完成后删除敏感文件 。然而,删除逻辑中存在的“自我排除”缺陷使这一控制机制失效,导致安装完成后,安装脚本仍然可以访问,从而允许非授权的用户创建账户。 截至本公告发
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| GetSimpleCMS | GetSimpleCMS | <= 3.4.0a |
affected |
| GetSimpleCMS-CE | GetSimpleCMS-CE | <= 3.3.22 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE | <= 3.3.22 | - |
|
| GetSimpleCMS | GetSimpleCMS | <= 3.4.0a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet