PT-2025-23259 · Unknown · Getsimple Cms

Mateusz-Sa

·

Published

2025-05-30

·

Updated

2025-06-01

·

CVE-2025-48492

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GetSimple CMS versions 3.3.16 through 3.3.21
Description The issue allows an authenticated user with access to the Edit component to inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote Code Execution (RCE). This issue is set to be patched in version 3.3.22.
Recommendations For versions 3.3.16 through 3.3.21, update to version 3.3.22 to resolve the issue. As a temporary workaround, consider restricting access to the Edit component to minimize the risk of exploitation.

Exploit

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-48492
GHSA-G435-P72M-P582

Affected Products

Getsimple Cms