Security Advisory
CVE-2016-5726
9.8
CRITICAL
Vulnerability Description
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
Published Date
February 9, 2017
Official Source
NIST NVD Advisory