Information disclosure in GetSimple CMS - CVE-2014-8723
Published: March 17, 2017 / Updated: August 8, 2020
GetSimple CMS
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation path in an error message.