An issue was discovered in Simple Machines Forum (SMF) before release 2.0.17. There is SSRF related to Subs-Package.php and Subs.php because user-supplied data is used directly in curl calls.
References
Link Resource
https://pastebin.com/raw/prE3iiLm Exploit Third Party Advisory
https://www.simplemachines.org/community/index.php?board=1.0 Release Notes Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-03-20T22:08:06

Updated: 2020-03-20T22:08:06

Reserved: 2019-04-27T00:00:00


Link: CVE-2019-11574

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-03-20T23:15:12.723

Modified: 2020-03-25T13:22:40.687


Link: CVE-2019-11574

JSON object: View

cve-icon Redhat Information

No data.

CWE