Simple Machines Forum contains a flaw related to the SSI.php failing to check for guest access permission during function calls. This may allow an attacker to call restricted functions and disclose 'Recent Posts' and 'Recent Topics' in forums which have guest access disabled.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Upgrade
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
OSVDB:
Web Related
Solution
Upgrade to version 1.1.13 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.