PT-2020-15096 · Getsimple · Getsimple Cms

Jadacheng

·

Published

2020-10-02

·

Updated

2020-10-13

·

CVE-2020-18191

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions GetSimpleCMS version 3.3.15
Description The issue allows remote attackers to delete arbitrary files. This is achieved through a directory traversal attack. The "/admin/log.php" API endpoint is involved in the exploitation.
Recommendations For GetSimpleCMS version 3.3.15, consider restricting access to the "/admin/log.php" endpoint until a patch is available. As a temporary workaround, avoid using the log.php file in the admin directory to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-18191

Affected Products

Getsimple Cms