CVE-2015-8973
high
CVSS v3
8.3
CVSS v2
7.5
VIR risk
8.3
Description
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.
Predictions
Exploit likelihood
89%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/
References
- http://www.openwall.com/lists/oss-security/2016/11/10/8
- http://www.openwall.com/lists/oss-security/2016/11/18/1
- http://www.securityfocus.com/bid/94397
- https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/
- http://www.openwall.com/lists/oss-security/2016/11/10/8
- http://www.openwall.com/lists/oss-security/2016/11/18/1
- http://www.securityfocus.com/bid/94397
- https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/
CWEs
CWE-284
Verify integrity in audit chain (admin only). AS-IS.