PT-2025-52716 · Mybb · Mybb

Luc1F3R11

·

Publicado

2025-12-22

·

Atualizado

2025-12-27

·

CVE-2023-53979

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MyBB version 1.8.32
Description MyBB version 1.8.32 contains a chained issue that allows authenticated administrators to bypass avatar upload restrictions and potentially execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface. The vulnerability involves bypassing restrictions on avatar uploads, which can lead to the execution of unauthorized code.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-53979

Produtos afetados

Mybb