Impact
Simple Machines Forum contains a server‑side request forgery flaw in its image proxy. The proxy accepts URLs embedded in BBCode image tags and fetches the referenced resource without validating the resolved destination against private address ranges, automatically generates HMAC signatures for any image URL, authenticated users can create valid signed proxy requests that target internal services – such as cloud metadata endpoints, internal web applications, and container network services – allowing the attacker to interact with resources that should be inaccessible from the public internet.
Affected Systems
The affected vendor is SimpleMachines, product SMF. Versions 2.1 and earlier before commit 4bf35cf and 3.0 and earlier before commit b4d23df are vulnerable.
Risk and Exploitability
With a CVSS score of 6 moderate severity. The EPSS score is less than 1% and the issue is not listed in CISA’s KEV catalog, indicating a low reported exploitation probability. However, exploitation requires an authenticated user who can embed arbitrary URLs in image tags. The attacker would need to set up a signed proxy request that resolves to a private internal address; once executed, the attacker could access sensitive internal resources, potentially exfiltrating information or executing further attacks from within the protected network.
OpenCVE Enrichment