← Vulnerability feed

Vulnerability record · CVE-2019-11231 · published 22 May 2019

CVE-2019-11231: GetSimple CMS theme-edit.php arbitrary file upload and auth bypass

Get Simple · Getsimple Cms

GetSimple CMS through 3.3.15 has insufficient input sanitation in admin/theme-edit.php, allowing an authenticated user to upload files with arbitrary content such as PHP code. Authentication can be bypassed by leaking the admin username and API key from data/other/authorization.xml and forging a session cookie based on a SHA-1 computation of known frontend information. The result is remote code execution on the server.

9.8 CVSS 3.0 Critical EPSS 72% · top 0.6% CWE-22 · Path traversal
9.8CVSS 3.0 base score, v2 5.0
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content (PHP code, for example). This vulnerability is triggered by an authenticated user; however, authentication can be bypassed. According to the official documentation for installation step 10, an admin is required to upload all the files, including the .htaccess files, and run a health check. However, what is overlooked is that the Apache HTTP Server by default no longer enables the AllowOverride directive, leading to data/users/admin.xml password exposure. The passwords are hashed but this can be bypassed by starting with the data/other/authorization.xml API key. This allows one to target the session state, since they decided to roll their own implementation. The cookie_name is crafted information that can be leaked from the frontend (site name and version). If a someone leaks the API key and the admin username, then they can bypass authentication. To do so, they need to supply a cookie based on an SHA-1 computation of this known information. The vulnerability exists in the admin/theme-edit.php file. This file checks for forms submissions via POST requests, and for the csrf nonce. If the nonce sent is correct, then the file provided by the user is uploaded. There is a path traversal allowing write access outside the jailed themes directory root. Exploiting the traversal is not necessary because the .htaccess file is ignored. A contributing factor is that there isn't another check on the extension before saving the file, with the assumption that the parameter content is safe. This allows the creation of web accessible and executable files with arbitrary content.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no required privileges, high EPSS, and public exploit code make this a high-risk remote code execution flaw.

What it is

GetSimple CMS through 3.3.15 has insufficient input sanitation in admin/theme-edit.php, allowing an authenticated user to upload files with arbitrary content such as PHP code. Authentication can be bypassed by leaking the admin username and API key from data/other/authorization.xml and forging a session cookie based on a SHA-1 computation of known frontend information. The result is remote code execution on the server.

Impact

An attacker can write and execute arbitrary PHP files on the web server, leading to full compromise of the CMS and potentially the underlying host. The CVSS 3.0 score is 9.8 critical with confidentiality, integrity and availability all rated high.

Attack surface

The flaw is reached over the network through the admin theme editor and session handling; the CVSS vector indicates no privileges or user interaction are required, and the description confirms authentication can be bypassed. Exploitation depends on obtaining the admin username and API key, which the description says can be leaked from the frontend and data files.

Exploitation

Public exploit references exist (Packet Storm and SSD disclosure), and EPSS is 0.71598 (99.387th percentile), indicating high likelihood of exploitation activity. The CVE is not listed in CISA KEV and no ransomware groups are documented using it.

What to do

  • Upgrade GetSimple CMS beyond 3.3.15 to a version that fixes the theme-edit.php upload and authentication bypass issues.
  • Restrict or disable the admin theme editor and file upload functionality where not required.
  • Ensure Apache AllowOverride is configured so .htaccess protections apply and data/ files such as admin.xml and authorization.xml are not web-accessible.
  • Rotate the GetSimple API key and admin credentials, and invalidate existing sessions after patching.
  • Deploy a WAF rule to block suspicious POST requests to admin/theme-edit.php and path traversal patterns in upload parameters.

Detection

  • Monitor web server logs for POST requests to admin/theme-edit.php, especially with file upload parameters or path traversal sequences.
  • Alert on creation or modification of executable files (for example .php) under the themes directory or outside expected upload paths.
  • Hunt for anomalous session cookies or authentication attempts that do not follow normal login flows, particularly those referencing SHA-1-derived cookie values.
  • Check for unauthorized access to data/users/admin.xml or data/other/authorization.xml and review file integrity on the CMS installation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-11231 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-41544Get-simple getsimple cms code injection vulnerabilityGetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.EPSS 11%8.8CVE-2018-17103Get-simple getsimple cms cross-site request forgery vulnerabilityAn issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. …EPSS 0.65%7.5CVE-2014-8722Get-simple getsimple cms information exposure vulnerabilityGetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/…EPSS 14%6.1CVE-2020-23839Get-simple getsimple cms cross-site scripting vulnerabilityA Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpage, allows remote attackers t…EPSS 10%6.1CVE-2013-1420Get-simple getsimple cms cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via t…EPSS 1.1%6.1CVE-2018-16325Get-simple getsimple cms cross-site scripting vulnerabilityThere is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.EPSS 0.80%6.1CVE-2018-9173Get-simple getsimple cms cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbit…EPSS 2.4%6.1CVE-2017-10673Get-simple getsimple cms cross-site scripting vulnerabilityadmin/profile.php in GetSimple CMS 3.x has XSS in a name field.EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2019-11231), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.