目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-53953— GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover

一分钟漏洞结论

影响对象
GetSimpleCMS-CE GetSimpleCMS-CE
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在版本 3.3.22 中,密码重置端点可在未进行身份验证的情况下被访问。当针对已存在的用户提交重置请求时,应用程序会生成一个新的临时密码,并立即将其哈希值存储为该用户的新密码。该临时密码使用 PHP 的 函数生成,其种子基于 。由于该种子基于时间且有效搜索空间有限,攻击者可以生成可能的重置密码候选值。此外,管理员登录端点未实施速率限制或账户锁定机制,因此攻击者可以在线逐一测试这些候选密码,直至找到正确密

CVSS 9.1 · Critical EPSS 0.06% · P20
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-53953 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover
来源: CVE Program / CVE List V5
Vulnerability Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates a new temporary password and immediately stores its hash as the user's new password. The temporary password is generated using PHP rand() seeded with microtime(). Because this seed is time-based and has a limited effective search space, an attacker can generate possible reset password candidates. Since the admin login endpoint does not enforce rate limiting or account lockout, these candidates can be tested online until the correct password is found. Successful exploitation may lead to administrator account takeover. At time of publication, there are no publicly available patches.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
使用具有密码学弱点缺陷的PRNG
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
GetSimpleCMS-CE GetSimpleCMS-CE = 3.3.22 -

二、漏洞 CVE-2026-53953 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-53953 的情报信息

请登录查看更多情报信息。

CVE-2026-53953 其他参考 (1)

同批安全公告 · GetSimpleCMS-CE · 2026-10-01 · 共 7 条

CVE-2026-56662 9.6 CRITICAL GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side
CVE-2026-56660 9.1 CRITICAL GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
CVE-2026-70650 8.8 HIGH GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco
CVE-2026-71542 8.7 HIGH GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/compon
CVE-2026-56661 7.5 HIGH GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
CVE-2026-71426 7.1 HIGH GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field

IV. Related Vulnerabilities

V. Comments for CVE-2026-53953

暂无评论


发表评论