Skip to content

A file write vulnerability exists in GetSimpleCMS

Num-Nine edited this page Oct 14, 2023 · 1 revision

1.GetSimple Version:3.4.0a

2.Download address:

https://codeload.github.com/GetSimpleCMS/GetSimpleCMS/zip/refs/heads/master

3.Vulnerability type: File write vulnerability

4.The following page is displayed in the background:

/admin/theme-edit.php?t=Innovation&f=functions.php

5.Write malicious code, such as phpinfo, in the functions.php file image-20231009233758083

Click save changes

6.Open file location:/theme/Innovation/functions.php

image-20231009233919817

Clone this wiki locally