PT-2025-52716 · Mybb · Mybb
Luc1F3R11
·
Publicado
2025-12-22
·
Atualizado
2025-12-27
·
CVE-2023-53979
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MyBB version 1.8.32
Description
MyBB version 1.8.32 contains a chained issue that allows authenticated administrators to bypass avatar upload restrictions and potentially execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface. The vulnerability involves bypassing restrictions on avatar uploads, which can lead to the execution of unauthorized code.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Correção
RCE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mybb