PT-2014-3298 · Simple Machines · Simple Machines Forum
Jakob Lell
·
Published
2014-04-29
·
Updated
2014-04-30
·
CVE-2013-7236
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple Machines Forum (SMF) versions 2.0.6 and earlier, 1.1.19 and earlier
Description
The issue allows remote attackers to impersonate arbitrary users by utilizing a Unicode homoglyph character in a
username. This can lead to unauthorized access and actions on behalf of the impersonated user.Recommendations
For versions 2.0.6 and earlier, update to a version that includes the fix for this issue.
For versions 1.1.19 and earlier, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting user registration to prevent the exploitation of this issue until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple Machines Forum