Description
SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers to have an unspecified impact via unknown vectors.
References (4)
Core 4
Core References
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/02/22/17
Patch x_refsource_confirm
http://www.simplemachines.org/community/index.php?topic=421547.0
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/03/02/4
Patch x_refsource_confirm
http://custom.simplemachines.org/mods/downloads/smf_patch_2.0-RC4_security.zip
Scores
EPSS
0.0221
EPSS Percentile
80.8%
Details
CWE
CWE-264
Status
published
Products (34)
simplemachines/smf
1.0 (7 CPE variants)
simplemachines/smf
1.0.1
simplemachines/smf
1.0.2
simplemachines/smf
1.0.3
simplemachines/smf
1.0.4
simplemachines/smf
1.0.5
simplemachines/smf
1.0.6
simplemachines/smf
1.0.7
simplemachines/smf
1.0.8
simplemachines/smf
1.0.9
... and 24 more
Published
Jun 21, 2011
Tracked Since
Feb 18, 2026