Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.
{
"cpe": "cpe:2.3:a:cagintranetworks:getsimple_cms:3.3.13_:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "3.3.13_"
},
{
"last_affected": "3.3.13_"
}
],
"source": "CPE_STRING"
}