CVE-2008-6971 describes a critical vulnerability in Simple Machines Forum (SMF) versions 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before 2.0 beta 4. The password reset functionality in these versions contained predictable validation codes and leaked random number generator state, allowing remote attackers to reset user passwords and gain unauthorized access. With a CVSS score of 7.5 (High) and a FAUCET Risk Score of 91/100, this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to full compromise of user accounts. While not listed on the KEV catalog or Hot List, an exploit for SMF 1.1.5 (Windows x86) is publicly available on ExploitDB, indicating a clear path for exploitation. Despite its age, the vulnerability has garnered minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.12CPE matchmatch criteria | cpe:2.3:a:simplemachines:smf:1.0.12:*:*:*:*:*:*:* | ||
1.0.13CPE matchmatch criteria | cpe:2.3:a:simplemachines:smf:1.0.13:*:*:*:*:*:*:* | ||
1.1.4CPE matchmatch criteria | cpe:2.3:a:simplemachines:smf:1.1.4:*:*:*:*:*:*:* | ||
1.1.5CPE matchmatch criteria | cpe:2.3:a:simplemachines:smf:1.1.5:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:simplemachines:smf:2.0:rc1.2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.