CVE-2026-56661: GetSimple CMS: Server-Side Request Forgery in the UpdateCE update endpoint
GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler fetches a user-supplied URL with filegetcontents() after only format validation (FILTERVALIDATEURL) — there is no validation of the request destination. An attacker who can submit the form can make the server issue requests to arbitrary destinations, including internal-only services and cloud metadata endpoints (169.254.169.254). The fetched response body is written to a web-accessible file (/Tmpfile.zip) and is not deleted when the content is not a valid ZIP, turning this into a full-read SSRF: the attacker can retrieve the response of the internal request directly. This issue has been patched in version 1.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GetSimple CMS CEto a version that resolves this vulnerability.Fixed in 1.5
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be able to submit the update form. The vulnerability has network attack vector and low attack complexity, but it requires high privileges and user interaction according to the supplied severity vector.
What can an attacker access through the vulnerable endpoint?
The server can be induced to request arbitrary destinations because only URL format validation is performed. This includes internal-only services and cloud metadata endpoints such as 169.254.169.254, and the response can be retrieved through the web-accessible /Tmpfile.zip file when it is not a valid ZIP.
Which versions are affected and what is the remediation?
GetSimple CMS CE versions prior to 1.5 are affected. Upgrade to version 1.5, which patches the issue.