SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator.
References
Link | Resource |
---|---|
https://github.com/sartlabs/0days/blob/main/SimpleMachinesForum/Exploit.txt | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-04-05 08:15
Updated : 2022-04-13 12:40
NVD link : CVE-2022-26982
Mitre link : CVE-2022-26982
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
simplemachines
- simple_machines_forum