First published: Tue Feb 21 2017(Updated: )
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CMS Made Simple Form Builder | <=0.8.1.5 | |
Simple CMS | <=1.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6071 is classified as a medium severity vulnerability due to the potential for information disclosure.
To fix CVE-2017-6071, update the CMS Made Simple Form Builder to version 0.8.1.6 or later.
CVE-2017-6071 allows remote attackers to conduct information-disclosure attacks through the exportxml feature.
CMS Made Simple versions prior to 1.12.3 and Form Builder versions up to 0.8.1.5 are affected by CVE-2017-6071.
Yes, CVE-2017-6071 specifically affects the Form Builder functionality within CMS Made Simple.