PT-2025-52716 · Mybb · Mybb
Luc1F3R11
·
Published
2025-12-22
·
Updated
2025-12-27
·
CVE-2023-53979
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MyBB version 1.8.32
Description
MyBB version 1.8.32 contains a chained issue that allows authenticated administrators to bypass avatar upload restrictions and potentially execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface. The vulnerability involves bypassing restrictions on avatar uploads, which can lead to the execution of unauthorized code.
Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mybb