PT-2018-9813 · Simple Machines · Simple Machines Forum

Daniel Le Gall

·

Published

2018-04-24

·

Updated

2019-10-03

·

CVE-2018-10305

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Simple Machines Forum (SMF) versions prior to 2.0.15
Description: The issue is related to the MessageSearch2 function in PersonalMessage.php, which does not properly utilize the possible users variable in a query. This might allow attackers to bypass intended access restrictions.
Recommendations: For versions prior to 2.0.15, update to version 2.0.15 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-10305

Affected Products

Simple Machines Forum