1.GetSimple Version:3.4.0a
2.Download address:
https://codeload.github.com/GetSimpleCMS/GetSimpleCMS/zip/refs/heads/master
3.Vulnerability type: File write vulnerability
4.The following page is displayed in the background:
/admin/theme-edit.php?t=Innovation&f=functions.php
5.Write malicious code, such as phpinfo, in the functions.php file
Click save changes
6.Open file location:/theme/Innovation/functions.php
There was an error while loading. Please reload this page.