CMSimple
cpe:2.3:a:cmsimple:cmsimple:*:*:*:*:*:*:*
- 5.16
A vulnerability in CMSimple version 5.16 allows remote attackers to obtain sensitive information. This is achieved by sending a crafted script to the 'validate link' function, which is susceptible to server-side request forgery (SSRF) attacks.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information or internal resources, depending on the target of the SSRF attack.
To reproduce this vulnerability, log in as an administrator and navigate to the edit mode of any page. Insert a link to a Burp Collaborator URL in the page editor. Once the link is validated, the request will be sent to Burp Collaborator, where the response can be checked for indications of accessing internal infrastructure.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.