Vulnerability in SMF 2.1.4 Allows for Remote Resource Identifier Control
CVE-2024-7438
4.3MEDIUM
Key Information:
- Vendor
Simplemachines
- Status
- Vendor
- CVE Published:
- 3 August 2024
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2024-7438?
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Version(s)
SMF 2.1.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.