Unrestricted File Upload Vulnerability in Simple Machines Forum
CVE-2013-4465

Currently unrated

Key Information:

Vendor
CVE Published:
25 October 2013

What is CVE-2013-4465?

The vulnerability in the avatar upload functionality of Simple Machines Forum allows remote authenticated users to upload files with executable extensions, facilitating the potential execution of arbitrary code. This risk arises when such malicious files are accessed through direct requests, providing an avenue for attackers to exploit the system. Affected users should upgrade to version 2.0.6 or later to mitigate this risk.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.