GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在版本 3.3.22 中,密码重置端点可在未进行身份验证的情况下被访问。当针对已存在的用户提交重置请求时,应用程序会生成一个新的临时密码,并立即将其哈希值存储为该用户的新密码。该临时密码使用 PHP 的 函数生成,其种子基于 。由于该种子基于时间且有效搜索空间有限,攻击者可以生成可能的重置密码候选值。此外,管理员登录端点未实施速率限制或账户锁定机制,因此攻击者可以在线逐一测试这些候选密码,直至找到正确密
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE | = 3.3.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56662 | 9.6 CRITICAL | GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side |
| CVE-2026-56660 | 9.1 CRITICAL | GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction |
| CVE-2026-70650 | 8.8 HIGH | GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco |
| CVE-2026-71542 | 8.7 HIGH | GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/compon |
| CVE-2026-56661 | 7.5 HIGH | GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint |
| CVE-2026-71426 | 7.1 HIGH | GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field |
No comments yet