CVE-2008-6971: High severity simple machines forum (smf) vulnerability
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4 includes clues about the random number generator state within a hidden form field and generates predictable validation codes, which allows remote attackers to modify passwords of other users and gain privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6971?
CVE-2008-6971 has a medium severity rating due to its potential to allow remote attackers to reset passwords.
How do I fix CVE-2008-6971?
To fix CVE-2008-6971, upgrade your Simple Machines Forum to version 1.0.14, 1.1.6, or 2.0 beta 4 or later.
What versions of Simple Machines Forum are affected by CVE-2008-6971?
CVE-2008-6971 affects Simple Machines Forum versions 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4.
What type of vulnerability is CVE-2008-6971?
CVE-2008-6971 is a vulnerability associated with predictable validation codes in the password reset functionality.
Who is at risk due to CVE-2008-6971?
Users of vulnerable versions of Simple Machines Forum are at risk as attackers could exploit the vulnerability to gain unauthorized access to accounts.