CVE-2014-8723: Infoleak
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymousdata.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8723?
CVE-2014-8723 has been classified as a medium severity vulnerability due to its potential to expose sensitive information.
How does CVE-2014-8723 affect GetSimple CMS?
CVE-2014-8723 allows remote attackers to access sensitive information through specific plugin files in GetSimple CMS version 3.3.4.
How do I fix CVE-2014-8723?
To fix CVE-2014-8723, it's recommended to restrict access to the vulnerable plugin files or upgrade to a patched version of GetSimple CMS.
What are the vulnerable components in CVE-2014-8723?
CVE-2014-8723 specifically affects plugins/anonymous_data.php and plugins/InnovationPlugin.php in GetSimple CMS 3.3.4.
Who is affected by CVE-2014-8723?
Any user or organization running GetSimple CMS version 3.3.4 may be affected by CVE-2014-8723 and is encouraged to take precautionary measures.