![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.142568 |
Category: | Web application abuses |
Title: | GetSimple CMS < 3.3.16 Multiple Vulnerabilities |
Summary: | GetSimple CMS is prone to multiple vulnerabilities. |
Description: | Summary: GetSimple CMS is prone to multiple vulnerabilities. Vulnerability Insight: The following vulnerabilities exist: - CVE-2019-9915: Open redirect via the 'admin/index.php' redirect parameter - CVE-2020-18191: Directory traversal in '/admin/log.php' may allow arbitrary file deletion - CVE-2020-18657: Cross Site Scripting (XSS) in 'admin/changedata.php' via the redirect_url parameter and the headers_sent function - CVE-2020-18658: XSS via the timezone parameter to 'settings.php' - CVE-2020-18659: XSS via the (1) sitename, (2) username, and (3) email parameters to '/admin/setup.php' - CVE-2020-18660: Open redirect in 'admin/changedata.php' via the redirect function to the url parameter - CVE-2021-28976: Remote Code Execution (RCE) in 'admin/upload.php' via phar files - CVE-2021-28977: XSS in 'admin/upload.php' by adding comments or jpg and other file header information to the content of xla, pages, and gzip files. Solution: Update to version 3.3.16 or later. CVSS Score: 6.5 CVSS Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2019-9915 https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1300 https://www.netsparker.com/web-applications-advisories/ns-18-056-open-redirection-vulnerability-in-getsimplecms/ Common Vulnerability Exposure (CVE) ID: CVE-2020-18657 https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1310 https://github.com/LoRexxar/CVE_Request/blob/master/getsimplecms%20v3.3.15/getsimplecms_before_v3.3.15.md https://www.seebug.org/vuldb/ssvid-97929 Common Vulnerability Exposure (CVE) ID: CVE-2020-18658 https://www.seebug.org/vuldb/ssvid-97930 Common Vulnerability Exposure (CVE) ID: CVE-2020-18659 https://www.seebug.org/vuldb/ssvid-97931 Common Vulnerability Exposure (CVE) ID: CVE-2020-18660 https://www.seebug.org/vuldb/ssvid-97928 Common Vulnerability Exposure (CVE) ID: CVE-2020-18191 https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1303 Common Vulnerability Exposure (CVE) ID: CVE-2021-28976 https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1335 Common Vulnerability Exposure (CVE) ID: CVE-2021-28977 https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1336 |
Copyright | Copyright (C) 2019 Greenbone Networks GmbH |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |