First published: Tue Feb 21 2017(Updated: )
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CMS Made Simple Form Builder | <=0.8.1.5 | |
Simple CMS | <=1.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6070 has a high severity rating as it allows remote attackers to execute arbitrary PHP code.
To mitigate CVE-2017-6070, upgrade CMS Made Simple Form Builder to version 0.8.1.6 or later.
CVE-2017-6070 affects versions of CMS Made Simple Form Builder prior to 0.8.1.6 and CMS Made Simple versions up to 1.12.2.
Yes, exploiting CVE-2017-6070 could allow an attacker to gain unauthorized access to sensitive data on the server.
The attack vector for CVE-2017-6070 involves sending specially crafted requests to the admin_store_form endpoint.