Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qf5-7jr3-q9pq

Опубликовано: 21 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

EPSS

Процентиль: 32%
0.00122
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-352

Связанные уязвимости

nvd
18 дней назад

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

EPSS

Процентиль: 32%
0.00122
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-352