PT-2014-3297 · Simple Machines · Simple Machines Forum

Jakob Lell

·

Published

2014-04-29

·

Updated

2014-04-30

·

CVE-2013-7235

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Machines Forum (SMF) versions prior to 1.1.19 Simple Machines Forum (SMF) versions 2.x prior to 2.0.6
Description The issue allows remote attackers to impersonate arbitrary users by utilizing multiple space characters.
Recommendations For Simple Machines Forum (SMF) versions prior to 1.1.19, update to version 1.1.19 or later. For Simple Machines Forum (SMF) versions 2.x prior to 2.0.6, update to version 2.0.6 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-7235

Affected Products

Simple Machines Forum