CVE-2007-1964: Medium severity MyBulletinBoard MyBulletinBoard vulnerability
member.php in MyBB (aka MyBulletinBoard), when debug mode is available, allows remote authenticated users to change the password of any account by providing the account's registered e-mail address in a debug request for a dolostpw action, which prints the change password verification code in the debug output.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1964?
CVE-2007-1964 has a moderate severity level due to its potential impact on user account security.
How do I fix CVE-2007-1964?
To fix CVE-2007-1964, it is recommended to upgrade MyBB to the latest version where the vulnerability is patched.
Who is affected by CVE-2007-1964?
CVE-2007-1964 affects MyBB version 1.2.5, impacting remote authenticated users who can exploit the debug mode.
What type of vulnerability is CVE-2007-1964?
CVE-2007-1964 is an account compromise vulnerability that allows unauthorized password changes.
Is debug mode safe to use in MyBB with CVE-2007-1964 present?
No, enabling debug mode in MyBB with CVE-2007-1964 can expose user accounts to unauthorized access risks.