First published: Fri Mar 20 2020(Updated: )
An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simplemachines Simple Machine Forum | <2.0.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11574 is critical.
CVE-2019-11574 affects Simple Machines Forum versions up to and including 2.0.17.
SSRF stands for Server-Side Request Forgery, which allows an attacker to make requests on behalf of a vulnerable server.
User-supplied data is used directly in curl calls in Subs-Package.php and Subs.php files, leading to SSRF vulnerabilities.
To fix CVE-2019-11574, you should update Simple Machines Forum to version 2.0.17 or later.