CVE-2022-39265 Information

Description

MyBB is a free and open source forum software. The Mail Settings ? Additional Parameters for PHP’s mail() function mail_parameters setting value in connection with the configured mail program’s options and behavior may allow access to sensitive information and Remote Code Execution (RCE). The vulnerable module requires Admin CP access with the _Can manage settings?_ permission and may depend on configured file permissions. MyBB 1.8.31 resolves this issue with the commit 0cd318136a. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Reference

https://mybb.com/versions/1.8.31/ https://github.com/mybb/mybb/security/advisories/GHSA-hxhm-rq9f-7xj7 https://github.com/mybb/mybb/commit/0cd318136a10b029bb5c8a8f6dddf39d87519797 https://github.com/mybb/mybb/blob/mybb_1830/install/resources/settings.xml#L2331-L2338

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction Required

HIGH

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.2

Share on: