CVE-2017-6071: Infoleak
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CMS Made Simple Form Builderto a version that resolves this vulnerability.Fixed in 0.8.1.6 - Compensating control
Restrict/limit remote access to functionality that triggers exportxml (the vulnerable export feature) until the Form Builder is upgraded to version 0.8.1.6 or later.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6071?
CVE-2017-6071 is classified as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2017-6071?
To fix CVE-2017-6071, update the CMS Made Simple Form Builder to version 0.8.1.6 or later.
What types of attacks does CVE-2017-6071 allow?
CVE-2017-6071 allows remote attackers to conduct information-disclosure attacks through the exportxml feature.
Which versions of CMS Made Simple are affected by CVE-2017-6071?
CMS Made Simple versions prior to 1.12.3 and Form Builder versions up to 0.8.1.5 are affected by CVE-2017-6071.
Is CVE-2017-6071 specific to any CMS functionalities?
Yes, CVE-2017-6071 specifically affects the Form Builder functionality within CMS Made Simple.