← Back

CVE-2014-8790

nvd nist
Published: Jan 20, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

XML external entity (XXE) vulnerability in admin/api.php in GetSimple CMS 3.1.1 through 3.3.x before 3.3.5 Beta 1, when in certain configurations, allows remote attackers to read arbitrary files via the data parameter.

Affected (11)

Getsimple Cms
1 product
Getsimple Cms
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Cagintranetworks
Version 3.3.3
Version 3.3.4
Get Simple
Version 3.1.1
Version 3.1.2
Version 3.2.1
Version 3.2.2
Version 3.2.3
Version 3.2
Version 3.3.0
Version 3.3.1
Version 3.3.2 b3

References (10)

Timeline

No history available yet.