Record summary

CVE-2019-9915 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMGetSimple CMS 3.3.13 - Open RedirectCVSS 6.1

GetSimple CMS 3.3.13 contains an open redirect vulnerability via the admin/index.php redirect parameter. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.

Remediation

Upgrade to the latest version of GetSimple CMS to fix the open redirect vulnerability.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2019redirectgetsimplecmsget-simple.vuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:get-simple.:getsimplecms:3.3.13:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3