VYPR
Critical severity9.8NVD Advisory· Published Apr 24, 2018· Updated Jun 17, 2026

CVE-2018-10305

CVE-2018-10305

Description

The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass intended access restrictions.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.