GetSimpleCMS 3.3.15 Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 17 May 2019.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a remote code execution vulnerability found in GetSimpleCMS versions 3.3.15 and below. An arbitrary file upload (PHPcode for example) vulnerability can be triggered by an authenticated user, however authentication can be bypassed by leaking the cms API key to target the session manager.

    Continue reading...
     

Share This Page

Loading...