Cross-site scripting (XSS) vulnerability in admin/filebrowser.php in GetSimple CMS before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the func parameter.
https://github.com/GetSimpleCMS/GetSimpleCMS/releases/tag/v3.3.6
https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1059
https://github.com/GetSimpleCMS/GetSimpleCMS/commit/cb1845743bd11ba74a49b6b522c080df86a17d51