Unrestricted File Upload Vulnerability in Simple Machines Forum
CVE-2013-4465
Currently unrated
What is CVE-2013-4465?
The vulnerability in the avatar upload functionality of Simple Machines Forum allows remote authenticated users to upload files with executable extensions, facilitating the potential execution of arbitrary code. This risk arises when such malicious files are accessed through direct requests, providing an avenue for attackers to exploit the system. Affected users should upgrade to version 2.0.6 or later to mitigate this risk.