GetSimple CMS through version 3.3.15 contains insufficient input sanitization in its administrative theme-editing functionality. An authenticated user who satisfies the anti-CSRF validation can upload arbitrary content, including PHP code, without an extension validation check. The upload functionality also permits path traversal outside the intended theme directory. Separately, an Apache configuration in which override directives are not enabled can expose administrator credential data. An attacker with the exposed API key and administrator username can construct a session cookie and bypass authentication, enabling access to the vulnerable upload function.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a working unauthenticated remote code execution (RCE) exploit for GetSimpleCMS versions 3.3.15 and below, targeting CVE-2019-11231. The exploit is implemented in Python (exploit.py) and automates the full attack chain: it leaks sensitive information (API salt and username) from publicly accessible files, forges a valid authentication cookie, retrieves a CSRF nonce, uploads a PHP web shell via the theme editor, and finally executes arbitrary system commands through the uploaded shell. The exploit requires only the target URL and an optional command to execute. The repository also includes a README.md with detailed usage instructions and a requirements.txt listing Python dependencies (requests, beautifulsoup4). The main attack vector is network-based, exploiting insecure file permissions and authentication logic in the CMS. The endpoints targeted are all HTTP paths exposed by the vulnerable CMS. The exploit is operational, providing a real web shell payload and full remote code execution capability.
This repository contains a single Metasploit module targeting GetSimpleCMS (versions 3.3.15 and earlier) for unauthenticated remote code execution (RCE), tracked as CVE-2019-11231. The exploit leverages a flaw in the CMS that allows an attacker to bypass authentication by leaking the API key and forging a valid session cookie. The module then uploads a malicious PHP file via the theme editor and executes it, granting the attacker arbitrary code execution on the server. The exploit is fully weaponized, allowing the user to supply any PHP payload supported by Metasploit. The code interacts with several HTTP endpoints on the target, including the admin panel, data directories, and theme editor. The repository is structured as a single Ruby file compatible with the Metasploit framework, and is intended for use by penetration testers or security researchers to demonstrate or test the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.