Multiple vulnerabilities in MyBB



| Updated: 2020-08-11
Risk High
Patch available NO
Number of vulnerabilities 3
CVE-ID CVE-2011-5131
CVE-2011-5132
CVE-2011-5133
CWE-ID CWE-352
CWE-79
CWE-20
Exploitation vector Network
Public exploit N/A
Vulnerable software
MyBB
Other software / Other software solutions

Vendor MyBB Group

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Cross-site request forgery

EUVDB-ID: #VU43650

Risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2011-5131

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.

Mitigation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

MyBB: 1.1.0 - 1.6.3

CPE2.3 External links

https://blog.mybb.com/2011/11/25/mybb-1-6-5-released-feature-update-security-maintenance-release/
https://dev.mybb.com/issues/1729
https://secunia.com/advisories/46951
https://www.osvdb.org/77327
https://www.securityfocus.com/bid/50816
https://exchange.xforce.ibmcloud.com/vulnerabilities/71462


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Cross-site scripting

EUVDB-ID: #VU43651

Risk: Low

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2011-5132

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Exploit availability: No

Description

Vulnerability allows a remote attacker to perform Cross-site scripting attacks.

An input validation error exists in MyBB before 1.6.5. A remote authenticated attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.

Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.

Mitigation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

MyBB: 1.1.0 - 1.6.3

CPE2.3 External links

https://blog.mybb.com/2011/11/25/mybb-1-6-5-released-feature-update-security-maintenance-release/
https://secunia.com/advisories/46951
https://www.osvdb.org/77326
https://www.securityfocus.com/bid/50816
https://exchange.xforce.ibmcloud.com/vulnerabilities/71461


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Input validation error

EUVDB-ID: #VU43652

Risk: High

CVSSv4.0: 8.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2011-5133

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Unspecified vulnerability in MyBB before 1.6.5 has unknown impact and attack vectors, related to an "unparsed user avatar in the buddy list."

Mitigation

Install update from vendor's website.

Vulnerable software versions

MyBB: 1.1.0 - 1.6.3

CPE2.3 External links

https://blog.mybb.com/2011/11/25/mybb-1-6-5-released-feature-update-security-maintenance-release/
https://secunia.com/advisories/46951
https://www.osvdb.org/77325
https://www.securityfocus.com/bid/50816


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###