Sceawere

Vulnerability Detail

CVE-2026-56660UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GetSimple CMS Arbitrary File Write

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
1d ago
Vendor
GetSimpleCMS-CE
Product
GetSimpleCMS-CE
Attack Type
CWE-352: Cross-Site Request Forgery (CSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction paths. Because PHP files are written into a web-accessible directory, an attacker who can cause a malicious archive to be processed achieves remote code execution as the web-server user. Entry names are also used unsafely, allowing directory traversal (../) to write files outside the intended extraction directory. This issue has been patched in version 1.5.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-01T20:17:26.643Z",
  "pubdate": "2026-10-01T20:17:26.643Z",
  "executiveSummary": "GetSimple CMS CE prior to version 1.5 contains a critical vulnerability in the update handler, UpdateCE.php, involving improper validation of ZIP archive contents.\nThe vulnerability is classified as an arbitrary file write, which facilitates remote code execution (RCE) on the underlying host.\nBy bypassing file type and path validation, an attacker can overwrite arbitrary files or plant malicious PHP code within the web root.\nThe flaw stems from unsafe extraction practices during the update process, allowing for directory traversal attacks.\nSuccessful exploitation allows an unauthenticated or authenticated attacker with control over the update source to execute arbitrary commands under the privileges of the web-server user.\nThe impact is severe, potentially leading to full system compromise, data exfiltration, and unauthorized service manipulation.",
  "technicalDetails": "The vulnerability resides in the UpdateCE.php component of GetSimple CMS CE, which is responsible for fetching and extracting software updates distributed as ZIP archives.\nThe primary root cause is the lack of sanitization and validation for the contents within the downloaded ZIP file. The application fails to inspect file extensions, allowing the extraction of arbitrary PHP scripts into web-accessible directories.\nFurthermore, the extraction logic fails to sanitize entry names within the ZIP archive. This omission enables path traversal attacks, where filenames containing '../' sequences allow the application to write files outside of the designated temporary extraction directory and into restricted locations within the web root or server filesystem.\nThe attack flow begins with an attacker successfully influencing the update mechanism to retrieve a malicious ZIP archive. Upon processing, the UpdateCE.php script iterates through the archive entries and extracts them directly onto the server's filesystem. Due to the lack of path validation, the application writes the malicious files to a target path defined by the attacker-controlled entry names.\nIf the attacker places a PHP webshell inside a public directory, they can trigger execution by requesting the file directly via HTTP. Because the server executes the file with the permissions of the web-server user (e.g., www-data), the attacker gains the ability to execute system commands, access configuration files, or modify site data.\nThis vulnerability is present in all versions prior to 1.5. Exploitation does not require sophisticated memory corruption techniques; it relies on the logical flaw in the archive handling procedure. The vulnerability poses a significant risk to any instance of GetSimple CMS CE using the native update feature, as it permits the persistence of malicious code and facilitates post-exploitation activities such as privilege escalation or lateral movement within the hosting environment."
}
CVE-2026-56660: GetSimple CMS Arbitrary File Write (CRITICAL Severity, CVSS: 9.1) | Sceawere