CVE detail
CVE-2021-29400 — CVE-2021-29400
Published 2021-08-10 · Modified 2026-06-17 · Vendor netexplorer · Product my_smtp_contact · Source nvd
MEDIUM
severity
CVSS-derived band
0.0056
EPSS probability
exploitation probability, 30d
43.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
A cross-site request forgery (CSRF) vulnerability in the My SMTP Contact v1.1.1 plugin for GetSimple CMS allows remote attackers to change the SMTP settings of the contact forms for the webpages of the CMS after an authenticated admin visits a malicious third-party site.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References