CVE-2011-4173: CSRF
Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication of administrators or moderators via vectors involving image files, a different vulnerability than CVE-2011-3615. NOTE: some of these details are obtained from third party information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4173?
CVE-2011-4173 is classified as a medium severity vulnerability due to its potential for CSRF attacks targeting the authentication of administrators or moderators.
How do I fix CVE-2011-4173?
To fix CVE-2011-4173, upgrade to Simple Machines Forum version 2.0.1 or later, which includes a patch for this vulnerability.
Who is affected by CVE-2011-4173?
CVE-2011-4173 affects installations of Simple Machines Forum 2.x before version 2.0.1, including multiple beta and release candidate versions.
What type of attack does CVE-2011-4173 facilitate?
CVE-2011-4173 facilitates cross-site request forgery (CSRF) attacks, allowing remote attackers to hijack user sessions.
Can I detect if I am vulnerable to CVE-2011-4173?
To detect vulnerability to CVE-2011-4173, check your Simple Machines Forum version against the affected versions listed in the CVE details.