PT-2018-10619 · Mybb · Moderator Log Notes Plugin

0Xb9

·

Published

2018-08-24

·

Updated

2018-10-31

·

CVE-2018-11502

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Moderator Log Notes plugin version 1.1 for MyBB
Description The issue allows an attacker to remotely delete all moderator notes and logs in the moderator control panel (modCP) and administrator control panel (ACP) via a Cross-Site Request Forgery (CSRF) attack. This enables unauthorized modification of sensitive data.
Recommendations For Moderator Log Notes plugin version 1.1, consider implementing CSRF protection mechanisms to prevent unauthorized requests. As a temporary workaround, restrict access to the modCP and ACP to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11502

Affected Products

Moderator Log Notes Plugin