CVE-2018-17103: Get-Simple Getsimple CMS

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter

Affected products

Published 2018-09-16. Last modified 2026-06-17.