|
Simple Machines Forum Password Reset Security Bypass Vulnerability
Simple Machines Forum is prone to a security-bypass vulnerability because it fails to adequately restrict access to the password-reset feature. An attacker can exploit this issue to gain administrative access to the application, which may allow the attacker to compromise the application; other attacks are also possible. Versions up to and including Simple Machines Forum 1.1.7 are vulnerable. UPDATE (February 6, 2009): The vendor indicates that this issue was resolved in Simple Machines Forum 1.0.14 and 1.1.6. |
|
|
Privacy Statement |