First published: Tue Apr 24 2018(Updated: )
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simplemachines Simple Machines Forum | <2.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-10305 is a vulnerability in Simple Machines Forum (SMF) before version 2.0.15 that allows attackers to bypass intended access restrictions.
CVE-2018-10305 has a severity rating of 9.8 (Critical).
The affected software for CVE-2018-10305 is Simple Machines Forum (SMF) before version 2.0.15.
An attacker can exploit CVE-2018-10305 by bypassing intended access restrictions in Simple Machines Forum (SMF).
Yes, the fix for CVE-2018-10305 is to update Simple Machines Forum (SMF) to version 2.0.15 or later.