Lucene search

K
cvelistMitreCVELIST:CVE-2018-10305
HistoryApr 24, 2018 - 2:00 a.m.

CVE-2018-10305

2018-04-2402:00:00
mitre
www.cve.org
4

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

55.6%

The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.

AI Score

9.5

Confidence

High

EPSS

0.002

Percentile

55.6%

Related for CVELIST:CVE-2018-10305