A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
History

Wed, 11 Sep 2024 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 10 Aug 2024 06:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273523. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Wed, 07 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Simplemachines
Simplemachines simple Machines Forum
CPEs cpe:2.3:a:simplemachines:simple_machines_forum:2.1.4:*:*:*:*:*:*:*
Vendors & Products Simplemachines
Simplemachines simple Machines Forum
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2024-08-03T15:31:03.669Z

Updated: 2024-08-10T06:26:12.241Z

Reserved: 2024-08-02T21:22:28.219Z

Link: CVE-2024-7438

cve-icon Vulnrichment

Updated: 2024-08-07T16:10:40.871Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-03T16:15:49.270

Modified: 2024-09-11T14:39:12.583

Link: CVE-2024-7438

cve-icon Redhat

No data.