XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Getsimple_cms | Cagintranetworks | 3.3.3 (including) | 3.3.3 (including) |
Getsimple_cms | Cagintranetworks | 3.3.4 (including) | 3.3.4 (including) |
Getsimple_cms | Get-simple | 3.1.1 (including) | 3.1.1 (including) |
Getsimple_cms | Get-simple | 3.1.2 (including) | 3.1.2 (including) |
Getsimple_cms | Get-simple | 3.2 (including) | 3.2 (including) |
Getsimple_cms | Get-simple | 3.2.1 (including) | 3.2.1 (including) |
Getsimple_cms | Get-simple | 3.2.2 (including) | 3.2.2 (including) |
Getsimple_cms | Get-simple | 3.2.3 (including) | 3.2.3 (including) |
Getsimple_cms | Get-simple | 3.3.0 (including) | 3.3.0 (including) |
Getsimple_cms | Get-simple | 3.3.1 (including) | 3.3.1 (including) |
Getsimple_cms | Get-simple | 3.3.2-b3 (including) | 3.3.2-b3 (including) |