Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-56662— GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request

Quick assessment

Affected
GetSimpleCMS-CE GetSimpleCMS-CE
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GetSimple CMS 是一款内容管理系统(CMS),而 GetSimple CMS CE 是该系统的社区版。在 1.5 版本之前,UpdateCE 更新表单中未包含任何防 CSRF(跨站请求伪造)令牌,且其 POST 处理程序也未执行任何令牌或请求来源验证。远程攻击者可以托管一个页面,该页面会自动向更新端点提交伪造的 POST 请求;当已认证的管理员访问该页面时,服务器将在管理员会话中执行由攻击者指定的下载并部署操作——无需进一步交互。由于所部署的内容会被执行(参见相关的 ZIP 解压安全公告),这将导致远程

CVSS 9.6 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56662

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request
Source: CVE Program / CVE List V5
Vulnerability Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨站请求伪造(CSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GetSimpleCMS-CE GetSimpleCMS-CE < 1.5 -

II. Public POCs for CVE-2026-56662

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56662

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-56662 (1)

Same Patch Batch · GetSimpleCMS-CE · 2026-10-01 · 7 CVEs total

CVE-2026-53953 9.1 CRITICAL GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover
CVE-2026-56660 9.1 CRITICAL GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
CVE-2026-70650 8.8 HIGH GetSimple CMS: Authenticated Stored XSS in backup viewer (backup-edit.php) via output deco
CVE-2026-71542 8.7 HIGH GetSimple CMS: Stored Cross-Site Scripting (XSS) via the "title" parameter in admin/compon
CVE-2026-56661 7.5 HIGH GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
CVE-2026-71426 7.1 HIGH GetSimple CMS: Authenticated Stored Local File Inclusion (LFI) via page "template" field

IV. Related Vulnerabilities

V. Comments for CVE-2026-56662

No comments yet


Leave a comment