Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

MyBB < 1.8.11 Multiple Vulnerabilities

High

Synopsis

The remote web server is running a PHP application that is vulnerable to multiple vulnerabilities.

Description

Versions of MyBB (MyBulletinBoard) prior to 1.8.11 are affected by the following vulnerabilities :

- The file 'usercp.php' contains an error that can allow server side request forgery (SSRF) via specially-crafted requests. (CVE-2017-7566) - An unspecified user-input error can allow cross-site scripting attacks (XSS). (CVE-2017-8103) - The file 'upload/admin/modules/config/smilies.php' contains a user-input validation error that can allow file disclosure via path traversal. (CVE-2017-8104)

Solution

Upgrade to MyBB version 1.8.11 or later.