PT-2026-21325 · Apache+1 · Apache+1
Twinson333
·
Publicado
2026-02-20
·
Atualizado
2026-02-24
·
CVE-2026-27161
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GetSimple CMS (affected versions not specified)
Description
GetSimple CMS is a content management system. All versions of GetSimple CMS depend on .htaccess files to restrict access to sensitive directories such as
/data/ and /backups/. If Apache AllowOverride is disabled, a common configuration in hardened or shared hosting environments, these protections are silently ignored. This allows unauthenticated attackers to list and download sensitive files, including authorization.xml, which contains cryptographic salts and API keys. The authorization.xml file contains sensitive information that could be used to compromise the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Apache
Getsimple Cms