CVE-2011-1129: XSS
Published Jun 21, 2011
·Updated
Cross-site scripting (XSS) vulnerability in the EditNews function in ManageNews.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, might allow remote authenticated users to inject arbitrary web script or HTML via a saveitems action.
Affected Software
57 affected components
SimpleMachines Smf=1.0.13
SimpleMachines Smf=1.1.2
SimpleMachines Smf=1.0.8
SimpleMachines Smf=1.1-rc1
SimpleMachines Smf=1.0-beta4.1
SimpleMachines Smf=1.0.1
SimpleMachines Smf<=1.1.12
SimpleMachines Smf=1.0.19
SimpleMachines Smf=1.0.7
SimpleMachines Smf=1.0.9
SimpleMachines Smf=1.0.10
SimpleMachines Smf=1.0-beta4
SimpleMachines Smf=1.1-beta3
SimpleMachines Smf=1.0-rc2
SimpleMachines Smf=1.1.4
SimpleMachines Smf=1.0.16
SimpleMachines Smf=1.0.14
SimpleMachines Smf=1.0.17
SimpleMachines Smf=1.1.10
SimpleMachines Smf=1.0-beta5
SimpleMachines Smf=1.1-beta1
SimpleMachines Smf=1.1
SimpleMachines Smf=1.1-beta2
SimpleMachines Smf=1.0.21
SimpleMachines Smf=1.1.11
SimpleMachines Smf=1.1.8
SimpleMachines Smf=1.0.2
SimpleMachines Smf=1.1.3
SimpleMachines Smf=1.1.7
SimpleMachines Smf=1.0.4
SimpleMachines Smf=1.1.5
SimpleMachines Smf=1.1.9
SimpleMachines Smf=1.0.12
SimpleMachines Smf=1.0.18
SimpleMachines Smf=1.1-beta4
SimpleMachines Smf=1.0.6
SimpleMachines Smf=1.0.20
SimpleMachines Smf=1.1-rc2
SimpleMachines Smf=1.0
SimpleMachines Smf=1.0.5
SimpleMachines Smf=1.0.15
SimpleMachines Smf=1.0-rc1
SimpleMachines Smf=1.1-rc3
SimpleMachines Smf=1.0.3
SimpleMachines Smf=1.0-beta6
SimpleMachines Smf=1.1.6
SimpleMachines Smf=1.1.1
SimpleMachines Smf=2.0-beta1
SimpleMachines Smf=2.0-beta3
SimpleMachines Smf=2.0-beta4
SimpleMachines Smf=2.0-beta2
SimpleMachines Smf=2.0-beta3.1
SimpleMachines Smf=2.0-beta2.1
SimpleMachines Smf=2.0-rc2
SimpleMachines Smf=2.0-rc3
SimpleMachines Smf=2.0-rc1
SimpleMachines Smf=2.0-rc4
Remediation
Patch Available
Patch Available
Event History
Jun 21, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-1129?
CVE-2011-1129 is considered a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2011-1129?
To fix CVE-2011-1129, upgrade Simple Machines Forum to version 1.1.13 or later, or 2.0 RC5 or later.
3
What versions of Simple Machines Forum are affected by CVE-2011-1129?
CVE-2011-1129 affects Simple Machines Forum versions prior to 1.1.13 and 2.0 RC5.
4
What is the impact of CVE-2011-1129?
The impact of CVE-2011-1129 allows remote authenticated users to inject arbitrary web scripts or HTML.
5
Who is at risk with CVE-2011-1129?
Remote authenticated users of affected Simple Machines Forum versions are at risk due to CVE-2011-1129.