Description
The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid login attempts, which might make it easier for remote attackers to obtain access or cause a denial of service via a brute-force attack.
References (4)
Core 4
Core References
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/02/22/17
Patch x_refsource_confirm
http://www.simplemachines.org/community/index.php?topic=421547.0
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2011/03/02/4
Patch x_refsource_confirm
http://custom.simplemachines.org/mods/downloads/smf_patch_2.0-RC4_security.zip
Scores
EPSS
0.0160
EPSS Percentile
73.2%
Details
CWE
CWE-310
Status
published
Products (34)
simplemachines/smf
1.0 (7 CPE variants)
simplemachines/smf
1.0.1
simplemachines/smf
1.0.2
simplemachines/smf
1.0.3
simplemachines/smf
1.0.4
simplemachines/smf
1.0.5
simplemachines/smf
1.0.6
simplemachines/smf
1.0.7
simplemachines/smf
1.0.8
simplemachines/smf
1.0.9
... and 24 more
Published
Jun 21, 2011
Tracked Since
Feb 18, 2026