CVE-2020-23839 describes a Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, specifically within the admin/index.php login portal. This flaw allows remote attackers to inject and execute malicious JavaScript code in a victim's browser if they click a crafted link, enter credentials, and submit the login form. Rated 6.1 MEDIUM on the CVSS scale, the vulnerability has a low attack complexity and requires user interaction, but can lead to credential harvesting and client-side code execution. While not listed on CISA's KEV catalog, an ExploitDB entry (EDB-49726) confirms the existence of exploit code, despite a lack of broader community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.3.16CPE matchmatch criteria | cpe:2.3:a:get-simple:getsimple_cms:3.3.16:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.