S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Feb 1, 2024

CVE-2019-9915 Scanner

Detects 'Open Redirect' vulnerability in GetSimple CMS affects v. 3.3.13.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-9915
6.1
CVSS

GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

GetSimple CMS is a Content Management System (CMS) designed to simplify the process of creating and managing websites. It’s a lightweight CMS, known for its ease of use, flexibility, and minimalistic interface. It’s an open-source software that has been in use since 2009. It’s based on PHP, and it stores its data in XML files instead of databases.

Recently, a vulnerability has been detected in GetSimple CMS, known as CVE-2019-9915. This vulnerability allows attackers to redirect users to malicious websites by manipulating the redirect parameter in the admin/index.php page. The attacker can exploit this vulnerability by crafting a malicious URL that appears to be legitimate, leading the user to believe they’re visiting a trusted website. Once the user clicks on the link, they’re redirected to a malicious site that can steal their sensitive information.

Exploiting this vulnerability can lead to a range of negative consequences. For instance, cybercriminals can use phishing attacks to trick users into sharing their login credentials, personal information, or financial data. This can result in identity theft, financial loss, and reputational damage. If the victim is a business, the attack could lead to downtime, diminished productivity, and lost revenue.

If you want to stay abreast of the latest vulnerabilities and security threats to your digital assets, you need a reliable source of information. s4e.io provides a platform that delivers curated and personalized reports on the security posture of your company and its digital properties. With pro features such as automated scanning, alerts, and threat intelligence feeds, you can rest assured that your website is protected against known and unknown risks. Invest in your digital security today and secure your website with s4e.io.

 

REFERENCES

Solution Advice

Fortunately, several precautions can be taken to protect against this vulnerability. Here are some effective countermeasures:

  • Install the latest version of GetSimple CMS and keep it up to date.
  • Restrict access to the admin page and create strong passwords.
  • Use firewalls, antivirus, and antimalware software to protect against attacks.
  • Set up IDS/IPS systems that can detect and prevent malicious traffic and movements.
  • Monitor logs and activity on your website, and investigate any unusual behavior.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-9915 scanner - Open Redirect vulnerability in GetSimple CMS | S4E