PT-2014-3296 · Simple Machines · Simple Machines Forum

Jakob Lell

·

Published

2014-04-29

·

Updated

2014-04-30

·

CVE-2013-7234

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Simple Machines Forum (SMF) versions prior to 1.1.19 Simple Machines Forum (SMF) versions 2.x prior to 2.0.6
Description The issue allows remote attackers to conduct clickjacking attacks. This is possible due to the lack of an appropriate X-Frame-Options header, which enables an attacker to frame the vulnerable application, potentially leading to unintended actions by the user.
Recommendations For versions prior to 1.1.19, update to version 1.1.19 or later. For versions 2.x prior to 2.0.6, update to version 2.0.6 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7234

Affected Products

Simple Machines Forum