vendor:
Simple Machines Forum (SMF)
by:
Xianur0
8.8
CVSS
HIGH
Cross-Site Request Forgery (XSRF)
352
CWE
Product Name: Simple Machines Forum (SMF)
Affected Version From: All
Affected Version To: All
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
SMF XSRF PoC By Xianur0
Xianur0 discovered a Cross-Site Request Forgery (XSRF) vulnerability in Simple Machines Forum (SMF). The vulnerability is located in the file Sources/PackageGet.php and allows an attacker to inject malicious code into the packages.xml file. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site when the malicious packages.xml file is loaded by the admin. The attacker can also use an iframe to load the malicious packages.xml file.
Mitigation:
The vendor has released an update to address this vulnerability. Users are advised to upgrade to the latest version.