High severity8.8NVD Advisory· Published Sep 25, 2020· Updated Jun 17, 2026
CVE-2020-23837
CVE-2020-23837
Description
A Cross-Site Request Forgery (CSRF) vulnerability in the Multi User plugin 1.8.2 for GetSimple CMS allows remote attackers to add admin (or other) users after an authenticated admin visits a third-party site or clicks on a URL.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:multi_user_project:multi_user:1.8.2:*:*:*:*:getsimple_cms:*:*
- GetSimple CMS/Multi User plugindescription
- Range: <=1.8.2
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/48745nvdExploitThird Party AdvisoryVDB Entry
- get-simple.info/extend/plugin/multi-user/133/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.