PT-2014-3298 · Simple Machines · Simple Machines Forum
Jakob Lell
·
Publicado
2014-04-29
·
Atualizado
2014-04-30
·
CVE-2013-7236
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple Machines Forum (SMF) versions 2.0.6 and earlier, 1.1.19 and earlier
Description
The issue allows remote attackers to impersonate arbitrary users by utilizing a Unicode homoglyph character in a
username. This can lead to unauthorized access and actions on behalf of the impersonated user.Recommendations
For versions 2.0.6 and earlier, update to a version that includes the fix for this issue.
For versions 1.1.19 and earlier, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting user registration to prevent the exploitation of this issue until a patch is available.
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Simple Machines Forum