Cross-Site Scripting Vulnerability in Simple Machines Forum by Simple Machines
CVE-2011-1129

Currently unrated

Key Information:

Status
Vendor
CVE Published:
21 June 2011

What is CVE-2011-1129?

A vulnerability exists in the EditNews function of ManageNews.php within Simple Machines Forum that allows remote authenticated users to inject arbitrary scripts or HTML through the 'save_items' action. This cross-site scripting flaw can be exploited to compromise user data and web application integrity, making it a significant security concern for instances running unsupported versions.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.
CVE-2011-1129 : Cross-Site Scripting Vulnerability in Simple Machines Forum by Simple Machines