GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request
Published Oct 1, 2026
9.6
CRITICALCVSS 3.1
Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.
Affected products
-
- Version < 1.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| GetSimpleCMS-CE | GetSimpleCMS-CE | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (1)
- https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-2rxv-4g4m-573w x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://github.com/GetSimpleCMS-CE/GetSimpleCMS-CE/security/advisories/GHSA-2rxv-4g4m-573w | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.