PT-2018-10303 · Mybb · Mybb Admin Notes Plugin
Published
2018-05-21
·
Updated
2018-06-25
·
CVE-2018-11092
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MyBB Admin Notes plugin version 1.1
Description
An issue allows an attacker to remotely delete all admin notes. This can be achieved via the "admin/index.php?empty=table" action, which is vulnerable to CSRF.
Recommendations
For MyBB Admin Notes plugin version 1.1, consider disabling the "empty=table" action in the admin/index.php file as a temporary workaround until a patch is available. Restrict access to the admin/index.php file to minimize the risk of exploitation.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mybb Admin Notes Plugin