CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://daylight-it.com/security-advisory-dlcs0001.html | third party advisory exploit |
http://dev.cmsmadesimple.org/project/files/69 | product |