MyBB 1.8.19 allows remote attackers to obtain sensitive information because it discloses the username upon receiving a password-reset request that lacks the code parameter.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://blog.mybb.com/2019/02/27/mybb-1-8-20-released-security-maintenance-release/ | release notes vendor advisory |
https://blog.mybb.com/ | release notes vendor advisory |