Vulnerability record · CVE-2019-11231 · published 22 May 2019
CVE-2019-11231: GetSimple CMS theme-edit.php arbitrary file upload and auth bypass
Get Simple · Getsimple Cms
GetSimple CMS through 3.3.15 has insufficient input sanitation in admin/theme-edit.php, allowing an authenticated user to upload files with arbitrary content such as PHP code. Authentication can be bypassed by leaking the admin username and API key from data/other/authorization.xml and forging a session cookie based on a SHA-1 computation of known frontend information. The result is remote code execution on the server.
Description
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows upload of files with arbitrary content (PHP code, for example). This vulnerability is triggered by an authenticated user; however, authentication can be bypassed. According to the official documentation for installation step 10, an admin is required to upload all the files, including the .htaccess files, and run a health check. However, what is overlooked is that the Apache HTTP Server by default no longer enables the AllowOverride directive, leading to data/users/admin.xml password exposure. The passwords are hashed but this can be bypassed by starting with the data/other/authorization.xml API key. This allows one to target the session state, since they decided to roll their own implementation. The cookie_name is crafted information that can be leaked from the frontend (site name and version). If a someone leaks the API key and the admin username, then they can bypass authentication. To do so, they need to supply a cookie based on an SHA-1 computation of this known information. The vulnerability exists in the admin/theme-edit.php file. This file checks for forms submissions via POST requests, and for the csrf nonce. If the nonce sent is correct, then the file provided by the user is uploaded. There is a path traversal allowing write access outside the jailed themes directory root. Exploiting the traversal is not necessary because the .htaccess file is ignored. A contributing factor is that there isn't another check on the extension before saving the file, with the assumption that the parameter content is safe. This allows the creation of web accessible and executable files with arbitrary content.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no required privileges, high EPSS, and public exploit code make this a high-risk remote code execution flaw.
What it is
GetSimple CMS through 3.3.15 has insufficient input sanitation in admin/theme-edit.php, allowing an authenticated user to upload files with arbitrary content such as PHP code. Authentication can be bypassed by leaking the admin username and API key from data/other/authorization.xml and forging a session cookie based on a SHA-1 computation of known frontend information. The result is remote code execution on the server.
Impact
An attacker can write and execute arbitrary PHP files on the web server, leading to full compromise of the CMS and potentially the underlying host. The CVSS 3.0 score is 9.8 critical with confidentiality, integrity and availability all rated high.
Attack surface
The flaw is reached over the network through the admin theme editor and session handling; the CVSS vector indicates no privileges or user interaction are required, and the description confirms authentication can be bypassed. Exploitation depends on obtaining the admin username and API key, which the description says can be leaked from the frontend and data files.
Exploitation
Public exploit references exist (Packet Storm and SSD disclosure), and EPSS is 0.71598 (99.387th percentile), indicating high likelihood of exploitation activity. The CVE is not listed in CISA KEV and no ransomware groups are documented using it.
What to do
- Upgrade GetSimple CMS beyond 3.3.15 to a version that fixes the theme-edit.php upload and authentication bypass issues.
- Restrict or disable the admin theme editor and file upload functionality where not required.
- Ensure Apache AllowOverride is configured so .htaccess protections apply and data/ files such as admin.xml and authorization.xml are not web-accessible.
- Rotate the GetSimple API key and admin credentials, and invalidate existing sessions after patching.
- Deploy a WAF rule to block suspicious POST requests to admin/theme-edit.php and path traversal patterns in upload parameters.
Detection
- Monitor web server logs for POST requests to admin/theme-edit.php, especially with file upload parameters or path traversal sequences.
- Alert on creation or modification of executable files (for example .php) under the themes directory or outside expected upload paths.
- Hunt for anomalous session cookies or authentication attempts that do not follow normal login flows, particularly those referencing SHA-1-derived cookie values.
- Check for unauthorized access to data/users/admin.xml or data/other/authorization.xml and review file integrity on the CMS installation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/152961/GetSimpleCMS-3.3.15-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://ssd-disclosure.com/?p=3899&preview=true | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/152961/GetSimpleCMS-3.3.15-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://ssd-disclosure.com/?p=3899&preview=true | ExploitThird Party Advisory |
Track CVE-2019-11231 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-11231), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.