CVE-2013-7236: Input Validation
Published Apr 29, 2014
·Updated
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.
Affected Software
55 affected components
SimpleMachines Simple Machines Forum<=1.1.9
SimpleMachines Simple Machines Forum=1.0
SimpleMachines Simple Machines Forum=1.0-beta4
SimpleMachines Simple Machines Forum=1.0-beta4.1
SimpleMachines Simple Machines Forum=1.0-beta5
SimpleMachines Simple Machines Forum=1.0-beta6
SimpleMachines Simple Machines Forum=1.0-rc1
SimpleMachines Simple Machines Forum=1.0-rc2
SimpleMachines Simple Machines Forum=1.0.1
SimpleMachines Simple Machines Forum=1.0.2
SimpleMachines Simple Machines Forum=1.0.3
SimpleMachines Simple Machines Forum=1.0.4
SimpleMachines Simple Machines Forum=1.0.5
SimpleMachines Simple Machines Forum=1.0.6
SimpleMachines Simple Machines Forum=1.0.7
SimpleMachines Simple Machines Forum=1.0.8
SimpleMachines Simple Machines Forum=1.0.9
SimpleMachines Simple Machines Forum=1.0.10
SimpleMachines Simple Machines Forum=1.0.12
SimpleMachines Simple Machines Forum=1.0.13
SimpleMachines Simple Machines Forum=1.0.14
SimpleMachines Simple Machines Forum=1.0.15
SimpleMachines Simple Machines Forum=1.0.16
SimpleMachines Simple Machines Forum=1.0.17
SimpleMachines Simple Machines Forum=1.0.18
SimpleMachines Simple Machines Forum=1.0.19
SimpleMachines Simple Machines Forum=1.0.20
SimpleMachines Simple Machines Forum=1.0.21
SimpleMachines Simple Machines Forum=1.0.22
SimpleMachines Simple Machines Forum=1.0.23
SimpleMachines Simple Machines Forum=1.1
SimpleMachines Simple Machines Forum=1.1-beta1
SimpleMachines Simple Machines Forum=1.1-beta2
SimpleMachines Simple Machines Forum=1.1-beta3
SimpleMachines Simple Machines Forum=1.1-beta4
SimpleMachines Simple Machines Forum=1.1-rc1
SimpleMachines Simple Machines Forum=1.1-rc2
SimpleMachines Simple Machines Forum=1.1-rc3
SimpleMachines Simple Machines Forum=1.1.1
SimpleMachines Simple Machines Forum=1.1.2
SimpleMachines Simple Machines Forum=1.1.3
SimpleMachines Simple Machines Forum=1.1.4
SimpleMachines Simple Machines Forum=1.1.5
SimpleMachines Simple Machines Forum=1.1.6
SimpleMachines Simple Machines Forum=1.1.7
SimpleMachines Simple Machines Forum=1.1.8
SimpleMachines Simple Machines Forum=1.1.10
SimpleMachines Simple Machines Forum=1.1.11
SimpleMachines Simple Machines Forum=1.1.12
SimpleMachines Simple Machines Forum=1.1.13
SimpleMachines Simple Machines Forum=1.1.14
SimpleMachines Simple Machines Forum=1.1.15
SimpleMachines Simple Machines Forum=1.1.16
SimpleMachines Simple Machines Forum=1.1.17
SimpleMachines Simple Machines Forum=2.0.6
Event History
Apr 29, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:38 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-7236?
CVE-2013-7236 has a medium severity rating, as it allows remote attackers to impersonate users without access to their credentials.
2
How do I fix CVE-2013-7236?
To fix CVE-2013-7236, upgrade to Simple Machines Forum version 2.0.7 or later, where the vulnerability has been patched.
3
What systems are affected by CVE-2013-7236?
CVE-2013-7236 affects Simple Machines Forum versions 2.0.6, 1.1.19, and all earlier versions.
4
Can CVE-2013-7236 be exploited easily?
Yes, CVE-2013-7236 can be exploited easily through the use of Unicode homoglyph characters in usernames.
5
What are the implications of CVE-2013-7236 for users?
The implications of CVE-2013-7236 include potential unauthorized access to user accounts, leading to privacy breaches and data manipulation.