The Custom JS plugin version 0.1 for GetSimple CMS suffers from a cross site request forgery vulnerability that allows remote unauthenticated attackers to inject arbitrary client-side code into authenticated administrators browsers, which results in remote code execution on the hosting server, when an authenticated administrator visits a malicious third party website.
37fb00eaa335aa6aa61ddf4f19d244b74484eafd86b630f87d5ad3af340ea879
GetSimple CMS Custom JS plugin version 0.1 suffers from cross site request forgery and cross site scripting vulnerabilities.
f8515a697bd43d6bc1e7a544b80861b8f892d912ba39ee0ded35abda0c9c0518