Unrated severityNVD Advisory· Published Oct 24, 2011· Updated Jun 16, 2026
CVE-2011-4173
CVE-2011-4173
Description
Cross-site request forgery (CSRF) vulnerability in Simple Machines Forum (SMF) 2.x before 2.0.1 allows remote attackers to hijack the authentication of administrators or moderators via vectors involving image files, a different vulnerability than CVE-2011-3615. NOTE: some of these details are obtained from third party information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:simplemachines:smf:2.0:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:simplemachines:smf:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:beta2.1:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:beta3.1:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:rc1.2:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:rc4:*:*:*:*:*:*
- cpe:2.3:a:simplemachines:smf:2.0:rc5:*:*:*:*:*:*
- (no CPE)range: <2.0.1
Patches
Vulnerability mechanics
References
4- secunia.com/advisories/46386nvdVendor Advisory
- www.simplemachines.org/community/index.phpnvdVendor Advisory
- openwall.com/lists/oss-security/2011/10/09/3nvd
- openwall.com/lists/oss-security/2011/10/10/6nvd
News mentions
0No linked articles in our index yet.