Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qf5-7jr3-q9pq

Опубликовано: 21 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.5

Описание

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

EPSS

Процентиль: 34%
0.00403
Низкий

5.1 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 6.5
nvd
8 месяцев назад

GetSimple CMS My SMTP Contact Plugin 1.1.1 contains a cross-site request forgery (CSRF) vulnerability. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, can change SMTP configuration settings in the plugin. This may allow unauthorized changes but does not directly enable remote code execution.

EPSS

Процентиль: 34%
0.00403
Низкий

5.1 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-352