Hybbs2 · Hybbs2 · CVE-2022-24677
**Name of the Vulnerable Software and Affected Versions**
HYBBS2 versions 2.3.2 and earlier
**Description**
The issue allows remote code execution because it writes plugin-related configuration information to conf.php. This is due to a problem in Admin.php.
**Recommendations**
For HYBBS2 versions 2.3.2 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.