CVE-2010-4626: Medium severity Mybb Mybb vulnerability
The myrand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mtrand function, which makes it easier for remote attackers to obtain access to an arbitrary account by requesting a reset of the account's password, and then conducting a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4626?
CVE-2010-4626 is categorized as a medium severity vulnerability due to the potential for remote attackers to exploit account access.
How do I fix CVE-2010-4626?
To fix CVE-2010-4626, update MyBB to version 1.4.12 or later, which addresses this vulnerability.
What impact does CVE-2010-4626 have on MyBB users?
CVE-2010-4626 allows remote attackers to gain access to user accounts through brute-force attacks on password reset mechanisms.
Which versions of MyBB are affected by CVE-2010-4626?
CVE-2010-4626 affects all MyBB versions prior to 1.4.12.
How can I determine if my MyBB installation is vulnerable to CVE-2010-4626?
Check your MyBB version; if it is earlier than 1.4.12, your installation is vulnerable to CVE-2010-4626.