CVE Vulnerabilities

CVE-2014-8790

Published: Jan 20, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.

Affected Software

NameVendorStart VersionEnd Version
Getsimple_cmsCagintranetworks3.3.3 (including)3.3.3 (including)
Getsimple_cmsCagintranetworks3.3.4 (including)3.3.4 (including)
Getsimple_cmsGet-simple3.1.1 (including)3.1.1 (including)
Getsimple_cmsGet-simple3.1.2 (including)3.1.2 (including)
Getsimple_cmsGet-simple3.2 (including)3.2 (including)
Getsimple_cmsGet-simple3.2.1 (including)3.2.1 (including)
Getsimple_cmsGet-simple3.2.2 (including)3.2.2 (including)
Getsimple_cmsGet-simple3.2.3 (including)3.2.3 (including)
Getsimple_cmsGet-simple3.3.0 (including)3.3.0 (including)
Getsimple_cmsGet-simple3.3.1 (including)3.3.1 (including)
Getsimple_cmsGet-simple3.3.2-b3 (including)3.3.2-b3 (including)

References