Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-39265: Version 1.8.31 - MyBB

MyBB is a free and open source forum software. The Mail Settings ? Additional Parameters for PHP’s mail() function mail_parameters setting value, in connection with the configured mail program’s options and behavior, may allow access to sensitive information and Remote Code Execution (RCE). The vulnerable module requires Admin CP access with the _Can manage settings?_ permission and may depend on configured file permissions. MyBB 1.8.31 resolves this issue with the commit 0cd318136a. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE
#vulnerability#git#php#rce

MyBB 1.8.31

04 October 2022

SecurityMaintenance

code 1831

Full Package

Install a new MyBB forum or upgrade from older versions.

.zip – 2.17 MB

Download from MyBB.com Download from GitHub.com (mirror)

sha512:

4ef308f6d30efef9a77656352738a88b669951a00b03016693374bb0f1e23f33f359f6996ff1a1d942be9079f16e930ea1a1bf0b6c74b5e285f2e6d6828a1a32

More checksums…

sha256:

e88354f10893512ea8f426aff9d6a48f7e2cb20bd3988b001c59c9f29084c2f1

sha1:

a5597131079417729378a1884ff8ec2db6d0e974

md5:

504a1a8464f5d5d456622b8da58df2ae

Changed Files

Upgrade from the previous version.

.zip – 0.63 MB

Download from MyBB.com Download from GitHub.com (mirror)

sha512:

92be080e0b00ed44492f0e23601a329b25d941c962b26b96e7a2bec045e3b73d8f8328f2030bf53073a58861d17b194b1ea1daf8ef6224b0468a07ff7678c587

More checksums…

sha256:

ace620b9997b68c9e1dd0348ab6b902c7800fbc0c182de51d1e389334521d3bd

sha1:

079bd493750f8be3e76490dda945f39862f79142

md5:

1e41c01c28a813349a44531447e648f7

How to verify packages

Upgrading to this Version

To upgrade: copy and overwrite the files, and run the install/ upgrade script.

Before performing any upgrade, remember to backup your forum’s files and database and store them safely.

If you have edited core files, including language files, please make sure you make a changelog for these changes so you can make them again (if necessary) once the upgrade is complete.

Follow the Upgrade Documentation for more detailed instructions.

Security Vulnerabilities Addressed (1)

Medium risk

Mail settings command parameter injection [1]

CWE-77 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2022-39265

Issues Resolved (21)View issues on GitHub

Changed Files ()

Changed Language Files (1)There are changes to 1 language file(s). Changed languages files can be cross-referenced from the list above.

Changed Templates (2)

  • private_send_tracking
  • video_twitch_embed

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907