Read Time:22 Second
Posted by Andrey Stoykov on Aug 17
# Exploit Title: Authenticated Code Injection – smfv2.1.4
# Date: 8/2024
# Exploit Author: Andrey Stoykov
# Version: 2.1.4
# Tested on: Ubuntu 22.04
# Blog:
https://msecureltd.blogspot.com/2024/06/friday-fun-pentest-series-7-smfv214.html
Code Injection Authenticated:
Steps to Reproduce:
1. Login as admin
2. Browse to “Current Theme”
3. Click on “Modify Themes” > “SMF Default Theme”
4. Click on…