CVE-2018-10305: Critical severity simple machines forum vulnerability
Published Apr 24, 2018
·Updated
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possibleusers variable in a query, which might allow attackers to bypass intended access restrictions.
Affected Software
1 affected component
SimpleMachines Simple Machines Forum<2.0.15
Event History
Apr 24, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-10305?
CVE-2018-10305 is a vulnerability in Simple Machines Forum (SMF) before version 2.0.15 that allows attackers to bypass intended access restrictions.
2
How severe is CVE-2018-10305?
CVE-2018-10305 has a severity rating of 9.8 (Critical).
3
What is the affected software for CVE-2018-10305?
The affected software for CVE-2018-10305 is Simple Machines Forum (SMF) before version 2.0.15.
4
How can an attacker exploit CVE-2018-10305?
An attacker can exploit CVE-2018-10305 by bypassing intended access restrictions in Simple Machines Forum (SMF).
5
Is there a fix available for CVE-2018-10305?
Yes, the fix for CVE-2018-10305 is to update Simple Machines Forum (SMF) to version 2.0.15 or later.