PT-2026-21325 · Apache+1 · Apache+1

Twinson333

·

Publicado

2026-02-20

·

Atualizado

2026-02-24

·

CVE-2026-27161

CVSS v4.0

8.7

Alta

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions GetSimple CMS (affected versions not specified)
Description GetSimple CMS is a content management system. All versions of GetSimple CMS depend on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled, a common configuration in hardened or shared hosting environments, these protections are silently ignored. This allows unauthenticated attackers to list and download sensitive files, including authorization.xml, which contains cryptographic salts and API keys. The authorization.xml file contains sensitive information that could be used to compromise the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27161
GHSA-F63G-XH6J-Q56G

Produtos afetados

Apache
Getsimple Cms