First published: Wed Jan 22 2020(Updated: )
An issue was discovered in Simple Machines Forum (SMF) before 2.0.16. Reverse tabnabbing can occur because of use of _blank for external links.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Simplemachines Simple Machines Forum | <2.0.16 | |
IBM Security Guardium | <=11.3 | |
IBM Security Guardium | <=11.4 | |
IBM Security Guardium | <=11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-12490 is a vulnerability in Simple Machines Forum (SMF) before version 2.0.16 that allows remote attackers to bypass security restrictions.
CVE-2019-12490 may impact IBM Security Guardium versions 11.3, 11.4, and 11.5, if the affected version of Simple Machines Forum (SMF) is installed.
Reverse tabnabbing is a technique that allows an attacker to exploit the trust a user has in a website by redirecting them to a malicious site after they have interacted with a legitimate link on the attacker's website.
An attacker can exploit CVE-2019-12490 by convincing a victim to visit a specially-crafted website, allowing the attacker to obtain the victim's credentials.
To fix CVE-2019-12490, upgrade Simple Machines Forum (SMF) to version 2.0.16 or later.