Remote Code Execution Vulnerability in GetSimple CMS by GetSimple Development
CVE-2025-48492
8.6HIGH
What is CVE-2025-48492?
GetSimple CMS has a vulnerability in versions 3.3.16 to 3.3.21 that allows an authenticated user with Edit component access to inject arbitrary PHP code into component files. This exploit can be executed using a specially crafted query string, potentially leading to Remote Code Execution on the affected system. A patch addressing this vulnerability is set to be released in version 3.3.22.
Affected Version(s)
GetSimpleCMS-CE >= 3.3.16, <= 3.3.21