SimpleMachinesForum 2.1.1 and earlier allows remote...
High severity
Unreviewed
Published
Apr 6, 2022
to the GitHub Advisory Database
•
Updated Mar 30, 2024
Description
Published by the National Vulnerability Database
Apr 5, 2022
Published to the GitHub Advisory Database
Apr 6, 2022
Last updated
Mar 30, 2024
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator.
References