PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-6072 Cmsmadesimple CVE debrief

CVE-2017-6072 is a publicly documented information-disclosure issue in CMS Made Simple Form Builder. The published record says remote attackers could trigger disclosure via defaultadmin, and NVD maps the weakness to CWE-200 with a network-based attack path that requires no privileges or user interaction.

Vendor
Cmsmadesimple
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-21
Original CVE updated
2026-05-13
Advisory published
2017-02-21
Advisory updated
2026-05-13

Who should care

Administrators and security teams running CMS Made Simple 1.x with the Form Builder component, especially where exposed admin or form data could reveal sensitive information. Hosting providers and managed service teams should also check for affected customer deployments.

Technical summary

The NVD record describes a confidentiality-only issue (CVSS 3.0: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). It lists Form Builder versions up to 0.8.1.5 as vulnerable and also maps CMS Made Simple versions up to 1.12.2. The CVE description states that remote attackers can conduct information-disclosure attacks via defaultadmin.

Defensive priority

Medium. The score is 5.3 and the impact is limited to confidentiality, but the attack is network-reachable and requires neither authentication nor user interaction.

Recommended defensive actions

  • Identify any CMS Made Simple deployments that include the Form Builder component.
  • Verify whether Form Builder is at version 0.8.1.5 or earlier and upgrade to 0.8.1.6 or later.
  • Check whether CMS Made Simple itself is within the vulnerable range listed by NVD (up to 1.12.2) and move to a non-vulnerable release.
  • Review administrative exposure around defaultadmin and remove unnecessary access paths.
  • Audit logs and application data for signs that sensitive information may have been exposed.
  • Retest after remediation to confirm the vulnerable component versions are no longer present.

Evidence notes

The CVE description supplied with the record states that CMS Made Simple version 1.x Form Builder before 0.8.1.6 allows remote information disclosure via defaultadmin. The NVD metadata maps the issue to CWE-200 and provides vulnerable CPE ranges for Form Builder up to 0.8.1.5 and CMS Made Simple up to 1.12.2. A third-party advisory reference is also listed in the record.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-6072 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-6072

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-6072 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-6072

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.