CVE-2020-18660: Medium severity getsimple cms vulnerability
Published Jun 23, 2021
·Updated
GetSimpleCMS <=3.3.15 has an open redirect in admin/changedata.php via the redirect function to the url parameter.
Affected Software
1 affected component
Get-simple Getsimplecms<=3.3.15
Event History
Jun 23, 2021
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
Description
Frequently Asked Questions
1
What is CVE-2020-18660?
CVE-2020-18660 is a vulnerability in GetSimpleCMS <=3.3.15 that allows an attacker to redirect users to malicious websites.
2
How severe is CVE-2020-18660?
CVE-2020-18660 has a severity rating of 6.1 (medium).
3
How does CVE-2020-18660 affect GetSimpleCMS?
CVE-2020-18660 affects GetSimpleCMS versions up to and including 3.3.15.
4
How can the open redirect vulnerability in GetSimpleCMS be exploited?
The open redirect vulnerability in GetSimpleCMS can be exploited through the redirect function in the admin/changedata.php file by manipulating the url parameter.
5
Is there a fix available for CVE-2020-18660?
Yes, upgrading GetSimpleCMS to version 3.3.16 or later fixes the open redirect vulnerability.