Remote Code Execution Vulnerability in CMS Made Simple Product by Daylight IT
CVE-2017-6070

9.8CRITICAL

Key Information:

Vendor
CVE Published:
21 February 2017

What is CVE-2017-6070?

A vulnerability exists in CMS Made Simple's Form Builder version 1.x prior to 0.8.1.6 that enables remote attackers to execute arbitrary PHP code. This exploitation can occur through manipulated parameters sent to the 'cntnt01fbrp_forma_form_template' within the admin_store_form function. As a result, unauthorized access and control over affected systems may be obtained, posing a significant risk to application integrity and confidentiality.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.