CVE-2026-28495: GetSimple CMS has CSRF to Remote Code Execution via Arbitrary PHP Write in gsconfig.php
GetSimple CMS is a content management system. The massiveAdmin plugin (v6.0.3) bundled with GetSimpleCMS-CE v3.3.22 allows an authenticated administrator to overwrite the gsconfig.php configuration file with arbitrary PHP code via the gsconfig editor module. The form lacks CSRF protection, enabling a remote unauthenticated attacker to exploit this via Cross-Site Request Forgery against a logged-in admin, achieving Remote Code Execution (RCE) on the web server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28495?
CVE-2026-28495 is considered a critical vulnerability due to its ability to allow remote code execution via CSRF.
How do I fix CVE-2026-28495?
To fix CVE-2026-28495, update your GetSimple CMS installation to the latest security patch that addresses this vulnerability.
Who is affected by CVE-2026-28495?
CVE-2026-28495 affects authenticated administrators using GetSimpleCMS-CE with the massiveAdmin plugin.
What are the potential consequences of CVE-2026-28495?
The potential consequences include unauthorized access, data loss, and remote code execution on the affected server.
Is there a workaround for CVE-2026-28495?
While a specific workaround is not officially provided, disabling the massiveAdmin plugin temporarily can mitigate the risk until a patch is applied.