Security Advisory

CVE-2014-8722

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-03-17 14:00:00
Last updated 2024-08-06 13:26:02
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.xml, or (4) data/other/appid.xml.