Remote Code Execution in Simple Machines Forum for Administrators
CVE-2022-26982

7.2HIGH

Key Information:

Vendor
CVE Published:
5 April 2022

What is CVE-2022-26982?

The SimpleMachinesForum software version 2.1.1 and prior is vulnerable to a remote code execution flaw that allows authenticated administrators to execute arbitrary PHP code. This occurs when administrators modify themes, as the system permits them to insert any PHP code they choose. While this functionality is intended for customization, it inadvertently opens a pathway for potential exploitation if an attacker gains administrative access. Maintaining strict control over administrator access and monitoring theme modifications is crucial to mitigate this risk.

References

EPSS Score

8% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.