CVE-2018-10305
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use th
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.
CRITICAL · CVSS 9.8
EPSS 0.004
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0