CVE-2014-8722
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
17/03/2017
Last modified:
20/04/2025
Description
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/.xml, (2) backups/users/.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:get-simple:getsimple_cms:3.3.4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://packetstormsecurity.com/files/162906/GetSimple-CMS-3.3.4-Information-Disclosure.html
- http://rossmarks.uk/portfolio.php
- http://rossmarks.uk/whitepapers/getSimple_cms_3.3.4.txt
- http://packetstormsecurity.com/files/162906/GetSimple-CMS-3.3.4-Information-Disclosure.html
- http://rossmarks.uk/portfolio.php
- http://rossmarks.uk/whitepapers/getSimple_cms_3.3.4.txt



