CVE-2008-0788: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of moderators or administrators for requests that delete threads via a domultideletethreads action to moderation.php and (2) hijack the authentication of arbitrary users for requests that delete private messages (PM) via a delete action to private.php.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0788?
CVE-2008-0788 has a high severity rating, as it allows remote attackers to exploit multiple CSRF vulnerabilities.
How do I fix CVE-2008-0788?
To fix CVE-2008-0788, upgrade MyBB to a version later than 1.2.11 that includes vulnerability patches.
What types of attacks are possible with CVE-2008-0788?
CVE-2008-0788 allows attackers to hijack the authentication of moderators and administrators to perform unauthorized actions such as deleting threads.
Which versions of MyBB are affected by CVE-2008-0788?
CVE-2008-0788 affects MyBB versions 1.2.11 and earlier.
Is CVE-2008-0788 a serious threat to MyBB users?
Yes, CVE-2008-0788 poses a serious threat as it can lead to unauthorized access and manipulation of moderator functionalities in MyBB.