Sceawere
Vulnerability Detail
CVE-2026-56662UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GetSimple CMS CE CSRF RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 1d ago
- Vendor
- GetSimpleCMS-CE
- Product
- GetSimpleCMS-CE
- Attack Type
- CWE-352: Cross-Site Request Forgery (CSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker can host a page that auto-submits a forged POST to the update endpoint; when an authenticated administrator visits it, the server performs an attacker-directed download-and-deploy operation in the administrator's session — with no further interaction. Because the deployed content is executed (see the related ZIP-extraction advisory), this yields remote code execution. The url field is additionally written into the form unescaped, providing a secondary HTML-injection sink via a malicious upgrade.json. This issue has been patched in version 1.5.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-10-01T20:17:26.950Z",
"pubdate": "2026-10-01T20:17:26.950Z",
"executiveSummary": "GetSimple CMS CE prior to version 1.5 is vulnerable to a critical Cross-Site Request Forgery (CSRF) attack leading to Remote Code Execution (RCE).\nThe vulnerability resides in the UpdateCE update form, which lacks anti-CSRF token verification and request-origin validation.\nA remote attacker can leverage this flaw by inducing an authenticated administrator to visit a malicious webpage, triggering an unauthorized, automated download-and-deploy operation of arbitrary content.\nBecause the system extracts and executes the deployed ZIP files, the exploit results in full system compromise.\nAdditionally, the update endpoint is susceptible to HTML injection due to improper escaping of the 'url' parameter within the upgrade.json process.\nThe risk is critical, as it requires no administrator interaction beyond visiting a malicious link, effectively bypassing administrative authentication boundaries.",
"technicalDetails": "The vulnerability originates from a deficiency in security controls within the UpdateCE update mechanism of GetSimple CMS CE versions prior to 1.5.\nThe root cause is the complete absence of anti-CSRF (Cross-Site Request Forgery) tokens and the failure of the POST handler to perform origin validation (such as checking the Referer or Origin headers).\nThe attack flow begins when an attacker hosts a malicious document configured to auto-submit a forged POST request to the target's update endpoint. When an authenticated administrator, possessing an active session, accesses the attacker-controlled page, the browser automatically attaches the session cookies to the forged request.\nThe server, lacking verification of the request's intent or origin, processes the malicious payload as a legitimate request.\nThe update function performs a download-and-deploy operation based on the attacker's inputs. Because the CMS architecture extracts and executes the contents of these ZIP files, the attacker can deliver a malicious package containing arbitrary scripts (e.g., PHP webshells) to be placed in an executable location on the web server.\nFurthermore, the application exhibits a secondary vulnerability: HTML injection. The 'url' field is processed and written into the form unescaped. An attacker can manipulate the 'upgrade.json' file content to inject malicious HTML, which is rendered in the administrator's context, facilitating potential session theft or administrative interface manipulation.\nThe combination of the CSRF vulnerability and the subsequent automatic execution of deployed ZIP-compressed archives creates a direct vector for persistent Remote Code Execution (RCE) without requiring prior system access or knowledge of the administrative credentials.\nThis vulnerability is classified as critical because it exploits the trusted relationship between the authenticated administrator and the CMS, and the lack of server-side validation transforms an administrative utility into an attacker-controlled remote deployment tool."
}