CVE-2012-4954: Vanillaforums Vanilla
Low severity, CVSS 3.5. EPSS: 1.1% chance of exploitation in the next 30 days.
The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.
Affected products
- Vanillaforums Vanilla: up to and including 2.0.18.4; version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; …
- Vanillaforums Vanilla Forums: up to and including 2.1
Published 2012-11-15. Last modified 2026-06-16.