Sceawere

Vulnerability Detail

CVE-2026-56661UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GetSimple CMS SSRF Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
1d ago
Vendor
GetSimpleCMS-CE
Product
GetSimpleCMS-CE
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with file_get_contents() after only format validation (FILTER_VALIDATE_URL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-01T20:17:26.793Z",
  "pubdate": "2026-10-01T20:17:26.793Z",
  "executiveSummary": "GetSimple CMS and GetSimple CMS CE prior to version 1.5 are susceptible to a Server-Side Request Forgery (SSRF) vulnerability within the update handler functionality. The vulnerability arises from improper input validation when processing user-supplied URLs for remote file retrieval.\nBy bypassing format-only validation, an attacker can force the server to perform arbitrary HTTP requests. This allows for interaction with internal network services and sensitive cloud metadata endpoints, such as 169.254.169.254. Because the application stores these responses in a web-accessible location, the vulnerability is elevated to a full-read SSRF, permitting the retrieval of internal data.\nThe risk is significant as it potentially exposes internal infrastructure that is not meant to be accessed from the public internet. Exploitation requires the attacker to have the ability to submit the vulnerable update form, making the impact dependent on the accessibility of the administrative interface. The flaw has been successfully mitigated in version 1.5.",
  "technicalDetails": "The root cause of the vulnerability lies in the improper implementation of remote resource fetching in the update handler. The application utilizes the PHP function file_get_contents() to retrieve data from a user-supplied URL. While the input undergoes validation via FILTER_VALIDATE_URL, this filter only ensures the syntax conforms to a URL format. It fails to implement allow-listing or restrictions on the destination host, protocol, or IP range.\nThe vulnerability flow initiates when an attacker submits a specifically crafted URL to the update handler. Because the application lacks server-side request destination validation, it initiates an outbound request to the target specified by the attacker. This enables the attacker to interact with the internal network architecture, including sensitive services such as internal databases, configuration APIs, or cloud metadata services (e.g., 169.254.169.254) which are often restricted to the local network.\nA critical aspect of this SSRF is the persistence of the retrieved data. The application writes the response body to a predictable, web-accessible file path: /Tmpfile.zip. The application's logic fails to sanitize or remove this file if the contents do not constitute a valid ZIP archive. Consequently, the attacker can verify the successful execution of the request and exfiltrate the data by accessing /Tmpfile.zip directly via their browser or an HTTP client. This transforms a blind SSRF into a full-read SSRF, as the attacker can retrieve the full response body of the internal request.\nAffected products include GetSimple CMS and GetSimple CMS CE versions prior to 1.5. Successful exploitation assumes the attacker has access to the form submission endpoint, which typically requires administrative or authenticated access depending on the CMS configuration. The exposure is limited to the server's network context, but the post-exploitation impact includes unauthorized information disclosure and potential reconnaissance of the internal network topology."
}
CVE-2026-56661: GetSimple CMS SSRF Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere