HIGH🇵🇱 Wersja polska

CVE-2022-26982

CVSS 7.2v3.1pub. 2022-04-05upd. 2024-11-21

SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the ability to modify themes, and can thus choose any PHP code that they wish to have executed on the server.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Simplemachines Simple Machines Forum

    APP
    Simplemachines
    ≤ 2.1.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2018-10305CRITICAL9.8PL ✓same product

SMF: obejście kontroli dostępu w wyszukiwaniu prywatnych wiadomości

CVE-2016-5726CRITICAL9.8PL ✓same product

PHP Object Injection w Simple Machines Forum 2.1 — zdalne wykonanie kodu

CVE-2009-5068HIGH7.2same product

There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On ...

CVE-2013-7466HIGH8.8same product

Simple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in instal...

CVE-2013-7468HIGH8.1same product

Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=e...