8.6 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): High (H)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): High (H)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
Simple Machines Forum < 2.1.7 Authorization Confusion via Profile::load()
Simple Machines Forum (SMF) through 2.1.7, fixed in commit 6f0dc61, contains an authorization state-confusion vulnerability in the profile loader that allows authenticated low-privileged users to gain administrator access by supplying multiple values for the user parameter. Attackers can exploit the mismatch between Profile::$member and User::$me->is_owner during sequential profile loading to be treated as the owner of an administrator profile, enabling unauthorized password changes and full account takeover.
References
-
Patch Commit patch
-
https://www.vulncheck.com/advisories/simple-machines-forum-authorization-confus… third-party-advisory
Affected products
- =<2.1.7
- ==6f0dc61958aa86a4b436a222f6176812ed5bbb95
Matching in nixpkgs
pkgs.smfh
Sleek Manifest File Handler
pkgs.asmfmt
Go assembler formatter
pkgs.libsmf
C library for reading and writing Standard MIDI Files
pkgs.nasmfmt
Formatter for NASM source files
-
nixos-unstable 2022-09-15
- nixpkgs-unstable 2022-09-15
- nixos-unstable-small 2022-09-15
-
nixos-26.05 2022-09-15
- nixos-26.05-small 2022-09-15
- nixpkgs-26.05-darwin 2022-09-15
pkgs.free5gc-smf
Open source 5G core network based on 3GPP R15
-
nixos-unstable -
- nixos-unstable-small 1.4.5
pkgs.mt32emu-smf2wav
Produces a WAVE file from a Standard MIDI file (SMF)
pkgs.python313Packages.pysmf
Python extension module for reading and writing Standard MIDI Files, based on libsmf
Package maintainers
-
@kalbasit Wael Nasreddine <wael.nasreddine@gmail.com>
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>
-
@eclairevoyant éclairevoyant
-
@Gerg-L Greg Leyda <gregleyda@proton.me>
-
@NotAShelf NotAShelf <raf@notashelf.dev>
-
@felbinger Nico Felbinger <nico@felbinger.eu>