Headline
CVE-2022-39265: Version 1.8.31 - MyBB
MyBB is a free and open source forum software. The Mail Settings ? Additional Parameters for PHP’s mail() function mail_parameters setting value, in connection with the configured mail program’s options and behavior, may allow access to sensitive information and Remote Code Execution (RCE). The vulnerable module requires Admin CP access with the _Can manage settings?_
permission and may depend on configured file permissions. MyBB 1.8.31 resolves this issue with the commit 0cd318136a
. Users are advised to upgrade. There are no known workarounds for this vulnerability.
MyBB 1.8.31
04 October 2022
SecurityMaintenance
code 1831
Full Package
Install a new MyBB forum or upgrade from older versions.
.zip – 2.17 MB
Download from MyBB.com Download from GitHub.com (mirror)
sha512:
4ef308f6d30efef9a77656352738a88b669951a00b03016693374bb0f1e23f33f359f6996ff1a1d942be9079f16e930ea1a1bf0b6c74b5e285f2e6d6828a1a32
More checksums…
sha256:
e88354f10893512ea8f426aff9d6a48f7e2cb20bd3988b001c59c9f29084c2f1
sha1:
a5597131079417729378a1884ff8ec2db6d0e974
md5:
504a1a8464f5d5d456622b8da58df2ae
Changed Files
Upgrade from the previous version.
.zip – 0.63 MB
Download from MyBB.com Download from GitHub.com (mirror)
sha512:
92be080e0b00ed44492f0e23601a329b25d941c962b26b96e7a2bec045e3b73d8f8328f2030bf53073a58861d17b194b1ea1daf8ef6224b0468a07ff7678c587
More checksums…
sha256:
ace620b9997b68c9e1dd0348ab6b902c7800fbc0c182de51d1e389334521d3bd
sha1:
079bd493750f8be3e76490dda945f39862f79142
md5:
1e41c01c28a813349a44531447e648f7
How to verify packages
Upgrading to this Version
To upgrade: copy and overwrite the files, and run the install/ upgrade script.
Before performing any upgrade, remember to backup your forum’s files and database and store them safely.
If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete.
Follow the Upgrade Documentation for more detailed instructions.
Security Vulnerabilities Addressed (1)
Medium risk
Mail settings command parameter injection [1]
CWE-77 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2022-39265
Issues Resolved (21)View issues on GitHub
Changed Files ()
Changed Language Files (1)There are changes to 1 language file(s). Changed languages files can be cross-referenced from the list above.
Changed Templates (2)
- private_send_tracking
- video_twitch_embed