Description
A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
References (1)
Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
http://get-simple.info/extend/plugin/my-smtp-contact/1221/
Scores
CVSS v3
6.5
EPSS
0.0056
EPSS Percentile
42.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Details
CWE
CWE-352
Status
published
Products (1)
netexplorer/my_smtp_contact
1.1.1
Published
Aug 10, 2021
Tracked Since
Feb 18, 2026