Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfw3-v3jx-w637

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.

xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.

EPSS

Процентиль: 59%
0.00384
Низкий

8.3 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.3
nvd
около 9 лет назад

xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.

EPSS

Процентиль: 59%
0.00384
Низкий

8.3 High

CVSS3

Дефекты

CWE-284