CVE-2018-17103: Get-Simple Getsimple CMS
High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter
Affected products
- Get-Simple Getsimple CMS: version 3.3.13 only
Published 2018-09-16. Last modified 2026-06-17.