### [CVE-2024-57549](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-57549) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen) ### Description CMSimple 5.16 allows the user to read cms source code through manipulation of the file name in the file parameter of a GET request. ### POC #### Reference - https://github.com/h4ckr4v3n/cmsimple5.16_research/blob/main/CMSimple%205.16%20Sensitive%20information%20disclosure.md #### Github - https://github.com/h4ckr4v3n/cmsimple5.16_research