The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://blog.mybb.com/2017/11/07/mybb-1-8-13-released-security-maintenance-release/ | release notes vendor advisory |
https://www.exploit-db.com/exploits/43136/ | exploit vdb entry third party advisory |