CVE-2017-6072: Infoleak
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CMS Made Simple Form Builderto a version that resolves this vulnerability.Fixed in 0.8.1.6
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6072?
CVE-2017-6072 is considered a medium-severity vulnerability due to its ability to allow information disclosure.
How do I fix CVE-2017-6072?
To fix CVE-2017-6072, you should upgrade to CMS Made Simple Form Builder version 0.8.1.6 or later.
Which versions of CMS Made Simple are affected by CVE-2017-6072?
CVE-2017-6072 affects CMS Made Simple Form Builder versions prior to 0.8.1.6 and CMS Made Simple versions up to 1.12.2.
What type of attack can CVE-2017-6072 facilitate?
CVE-2017-6072 can facilitate remote information-disclosure attacks through default administrative accounts.
Is CVE-2017-6072 still a risk if I have upgraded my CMS Made Simple software?
If you have upgraded to the patched versions, CVE-2017-6072 should no longer pose a risk.