PT-2026-24402 · WordPress+1 · Massiveadmin+1
Dxleryt
·
Published
2026-03-10
·
Updated
2026-03-10
·
CVE-2026-28495
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GetSimple CMS versions 3.3.22
massiveAdmin plugin version 6.0.3
Description
GetSimple CMS, when used with the massiveAdmin plugin version 6.0.3, allows an authenticated administrator to overwrite the
gsconfig.php configuration file with arbitrary PHP code through the gsconfig editor module. The form lacks Cross-Site Request Forgery (CSRF) protection, enabling a remote unauthenticated attacker to exploit this through CSRF against a logged-in administrator, potentially leading to Remote Code Execution (RCE) on the web server. This can be triggered by a malicious email containing an embedded form, resulting in a full server compromise.Recommendations
For GetSimple CMS version 3.3.22 and massiveAdmin plugin version 6.0.3, ensure proper CSRF protection is implemented for the gsconfig editor module to prevent unauthorized modification of the
gsconfig.php file.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Getsimple Cms
Massiveadmin