CVE-2011-5131: CSRF
Cross-site request forgery (CSRF) vulnerability in global.php in MyBB before 1.6.5 allows remote attackers to hijack the authentication of a user for requests that change the user's language via the language parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5131?
CVE-2011-5131 has a severity rating that can affect the authentication of users in MyBB versions prior to 1.6.5.
How do I fix CVE-2011-5131?
To fix CVE-2011-5131, upgrade MyBB to version 1.6.5 or later, where the vulnerability has been patched.
What can attackers achieve through CVE-2011-5131?
Attackers exploiting CVE-2011-5131 can hijack a user's session and change their language settings without their consent.
Which versions of MyBB are affected by CVE-2011-5131?
CVE-2011-5131 affects all MyBB versions prior to 1.6.5, including various versions from 1.1.0 to 1.6.4.
How does CVE-2011-5131 impact user security?
CVE-2011-5131 compromises user security by allowing unauthorized language changes that could mislead users or disrupt user experience.