CVE-2025-48492: GetSimple CMS RCE in Edit component
GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with access to the Edit component can inject arbitrary PHP into a component file and execute it via a crafted query string, resulting in Remote Code Execution (RCE). This issue is set to be patched in version 3.3.22.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48492?
CVE-2025-48492 is considered critical due to its potential for Remote Code Execution (RCE).
How do I fix CVE-2025-48492?
To mitigate CVE-2025-48492, upgrade GetSimple CMS to version 3.3.22 or later where the vulnerability has been patched.
Who is affected by CVE-2025-48492?
Any authenticated user with access to the Edit component of GetSimple CMS versions 3.3.16 to 3.3.21 is affected by CVE-2025-48492.
What type of vulnerability is CVE-2025-48492?
CVE-2025-48492 is a Remote Code Execution (RCE) vulnerability.
What actions can attackers perform due to CVE-2025-48492?
Attackers can inject and execute arbitrary PHP code through a crafted query string due to CVE-2025-48492.