BIT-mybb-2021-43281

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/mybb/BIT-mybb-2021-43281.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-mybb-2021-43281
Aliases
  • CVE-2021-43281
Published
2024-03-06T10:58:37.178Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type "php" with PHP code, executed on Change Settings pages.

Database specific
{
    "cpes": [
        "cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / mybb

Package

Name
mybb
Purl
pkg:bitnami/mybb

Severity

  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
1.2.0
Fixed
1.8.29