affected product: GetSimpleCMS CE
version: 3.3.19.
First, go to the backend management page and click on the plugins button, and click ‘Download more pulgins’.
the function point ‘Download’ suffers from SSRF vulnerability.
create a new file ‘maa.php’, it’s contents are as follows:
put it into folder ‘test’ , and zip the ‘test’ folder
start python’s http server, change the paramater to enable the server download our ‘test’ plugin
visit admin/plugins.php to see the newly installed plugin
Make it active and refresh the page
Success rce