xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.
References
Link | Resource |
---|---|
https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/ | Release Notes Vendor Advisory |
http://www.openwall.com/lists/oss-security/2016/11/18/1 | Mailing List Third Party Advisory |
http://www.openwall.com/lists/oss-security/2016/11/10/8 | Third Party Advisory |
http://www.securityfocus.com/bid/94397 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-01-31 14:59
Updated : 2017-02-05 13:11
NVD link : CVE-2015-8973
Mitre link : CVE-2015-8973
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
mybb
- merge_system
- mybb