CVE-2013-7235: Input Validation
Published Apr 29, 2014
·Updated
Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to impersonate arbitrary users via multiple space characters characters.
Affected Software
71 affected components
SimpleMachines Simple Machines Forum<=1.1.9
SimpleMachines Simple Machines Forum=1.0
SimpleMachines Simple Machines Forum=1.0-beta4
SimpleMachines Simple Machines Forum=1.0-beta4.1
SimpleMachines Simple Machines Forum=1.0-beta5
SimpleMachines Simple Machines Forum=1.0-beta6
SimpleMachines Simple Machines Forum=1.0-rc1
SimpleMachines Simple Machines Forum=1.0-rc2
SimpleMachines Simple Machines Forum=1.0.1
SimpleMachines Simple Machines Forum=1.0.2
SimpleMachines Simple Machines Forum=1.0.3
SimpleMachines Simple Machines Forum=1.0.4
SimpleMachines Simple Machines Forum=1.0.5
SimpleMachines Simple Machines Forum=1.0.6
SimpleMachines Simple Machines Forum=1.0.7
SimpleMachines Simple Machines Forum=1.0.8
SimpleMachines Simple Machines Forum=1.0.9
SimpleMachines Simple Machines Forum=1.0.10
SimpleMachines Simple Machines Forum=1.0.12
SimpleMachines Simple Machines Forum=1.0.13
SimpleMachines Simple Machines Forum=1.0.14
SimpleMachines Simple Machines Forum=1.0.15
SimpleMachines Simple Machines Forum=1.0.16
SimpleMachines Simple Machines Forum=1.0.17
SimpleMachines Simple Machines Forum=1.0.18
SimpleMachines Simple Machines Forum=1.0.19
SimpleMachines Simple Machines Forum=1.0.20
SimpleMachines Simple Machines Forum=1.0.21
SimpleMachines Simple Machines Forum=1.0.22
SimpleMachines Simple Machines Forum=1.0.23
SimpleMachines Simple Machines Forum=1.1
SimpleMachines Simple Machines Forum=1.1-beta1
SimpleMachines Simple Machines Forum=1.1-beta2
SimpleMachines Simple Machines Forum=1.1-beta3
SimpleMachines Simple Machines Forum=1.1-beta4
SimpleMachines Simple Machines Forum=1.1-rc1
SimpleMachines Simple Machines Forum=1.1-rc2
SimpleMachines Simple Machines Forum=1.1-rc3
SimpleMachines Simple Machines Forum=1.1.1
SimpleMachines Simple Machines Forum=1.1.2
SimpleMachines Simple Machines Forum=1.1.3
SimpleMachines Simple Machines Forum=1.1.4
SimpleMachines Simple Machines Forum=1.1.5
SimpleMachines Simple Machines Forum=1.1.6
SimpleMachines Simple Machines Forum=1.1.7
SimpleMachines Simple Machines Forum=1.1.8
SimpleMachines Simple Machines Forum=1.1.10
SimpleMachines Simple Machines Forum=1.1.11
SimpleMachines Simple Machines Forum=1.1.12
SimpleMachines Simple Machines Forum=1.1.13
SimpleMachines Simple Machines Forum=1.1.14
SimpleMachines Simple Machines Forum=1.1.15
SimpleMachines Simple Machines Forum=1.1.16
SimpleMachines Simple Machines Forum=1.1.17
SimpleMachines Simple Machines Forum=2.0-beta1
SimpleMachines Simple Machines Forum=2.0-beta2
SimpleMachines Simple Machines Forum=2.0-beta2.1
SimpleMachines Simple Machines Forum=2.0-beta3
SimpleMachines Simple Machines Forum=2.0-beta3.1
SimpleMachines Simple Machines Forum=2.0-beta4
SimpleMachines Simple Machines Forum=2.0-rc1
SimpleMachines Simple Machines Forum=2.0-rc2
SimpleMachines Simple Machines Forum=2.0-rc3
SimpleMachines Simple Machines Forum=2.0-rc4
SimpleMachines Simple Machines Forum=2.0-rc5
SimpleMachines Simple Machines Forum=2.0.1
SimpleMachines Simple Machines Forum=2.0.2
SimpleMachines Simple Machines Forum=2.0.3
SimpleMachines Simple Machines Forum=2.0.4
SimpleMachines Simple Machines Forum=2.0.5
SimpleMachines Simple Machines Forum=2.0.6
Event History
Apr 29, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:38 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7235?
CVE-2013-7235 has a medium severity rating, posing a significant risk of user impersonation.
2
How do I fix CVE-2013-7235?
To fix CVE-2013-7235, upgrade Simple Machines Forum to version 2.0.6 or higher.
3
What versions of Simple Machines Forum are affected by CVE-2013-7235?
CVE-2013-7235 affects Simple Machines Forum versions before 1.1.19 and 2.x before 2.0.6.
4
Can CVE-2013-7235 lead to unauthorized access?
Yes, CVE-2013-7235 can allow remote attackers to impersonate arbitrary users, leading to unauthorized access.
5
What type of vulnerability is CVE-2013-7235 categorized as?
CVE-2013-7235 is categorized as an authentication vulnerability.