What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in Code Parrots Easy Forms for Mailchimp.This issue affects Easy Forms for Mailchimp: from n/a through 6.9.0.
Explanation of Vulnerability in Simple Terms
Easy Forms for Mailchimp versions up to 6.9.0 expose sensitive information in form submissions and plugin data. An attacker on the network can read this data without authentication. The vulnerability stems from insufficient access controls on data storage or transmission. Site administrators should update to a version newer than 6.9.0 immediately.
What an attacker can do
Read sensitive form submission data and plugin information without logging in.
Potential impact on your site
Form submissions containing user data (emails, names, etc.) may be exposed to unauthenticated attackers.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities