PT-2022-18161 · Unknown · Simple Machines Forum

Cyberinsane

+1

·

Published

2022-04-05

·

Updated

2024-08-03

·

CVE-2022-26982

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SimpleMachinesForum versions 2.1.1 and earlier
Description The issue allows remote authenticated administrators to execute arbitrary code by inserting vulnerable PHP code because themes can be modified by an administrator. The vendor's position is that administrators are intended to have the ability to modify themes and can thus choose any PHP code to be executed on the server.
Recommendations For SimpleMachinesForum versions 2.1.1 and earlier, as a temporary workaround, consider restricting theme modification capabilities to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-26982

Affected Products

Simple Machines Forum