CVE-2011-1128: High severity SimpleMachines Smf vulnerability
The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid login attempts, which might make it easier for remote attackers to obtain access or cause a denial of service via a brute-force attack.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1128?
CVE-2011-1128 is considered a high severity vulnerability that can potentially allow remote attackers to obtain unauthorized access or cause denial of service.
How do I fix CVE-2011-1128?
To fix CVE-2011-1128, upgrade your Simple Machines Forum to version 1.1.13 or 2.0 RC5 and above.
What versions of Simple Machines Forum are affected by CVE-2011-1128?
CVE-2011-1128 affects Simple Machines Forum versions before 1.1.13 and all 2.x versions prior to 2.0 RC5.
What is the impact of CVE-2011-1128 on my Simple Machines Forum installation?
The impact of CVE-2011-1128 can include unauthorized access through brute-force attacks and potential denial of service.
Is there a workaround for CVE-2011-1128 if I cannot update immediately?
If you cannot update immediately, consider implementing rate limiting or CAPTCHA on login attempts to mitigate brute-force attack risks.