CVE-2015-2352: High severity mybb vulnerability
Published Mar 19, 2015
·Updated
The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding of input to the varexport function, which allows attackers to have an unspecified impact via unknown vectors.
Affected Software
1 affected component
Mybb Mybb<=1.8.3
Remediation
Event History
Mar 19, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-2352?
CVE-2015-2352 is considered a medium severity vulnerability due to inadequate input validation.
2
How do I fix CVE-2015-2352?
To fix CVE-2015-2352, upgrade MyBB to version 1.8.4 or later.
3
What systems are affected by CVE-2015-2352?
CVE-2015-2352 affects MyBB versions prior to 1.8.4.
4
What exploitation methods are possible with CVE-2015-2352?
The vulnerability may allow attackers to manipulate the input to the var_export function, leading to an unknown impact.
5
Is there a patch available for CVE-2015-2352?
Yes, a patch is included in the update to MyBB version 1.8.4.