PT-2026-21325 · Apache+1 · Apache+1
Twinson333
·
Published
2026-02-20
·
Updated
2026-02-24
·
CVE-2026-27161
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GetSimple CMS (affected versions not specified)
Description
GetSimple CMS is a content management system. All versions of GetSimple CMS depend on .htaccess files to restrict access to sensitive directories such as
/data/ and /backups/. If Apache AllowOverride is disabled, a common configuration in hardened or shared hosting environments, these protections are silently ignored. This allows unauthenticated attackers to list and download sensitive files, including authorization.xml, which contains cryptographic salts and API keys. The authorization.xml file contains sensitive information that could be used to compromise the system.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache
Getsimple Cms