CVE-2018-10305
24.04.2018, 02:29
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.Enginsight
Vendor | Product | Version |
---|---|---|
simplemachines | simple_machines_forum | 𝑥 < 2.0.15 |
𝑥
= Vulnerable software versions