First published: Tue Jan 31 2017(Updated: )
xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MyBB | <=1.8.5 | |
MyBB | <=1.6.17 | |
MyBB | =1.8.0 | |
MyBB | =1.8.1 | |
MyBB | =1.8.2 | |
MyBB | =1.8.3 | |
MyBB | =1.8.4 | |
MyBB | =1.8.5 | |
<=1.8.5 | ||
<=1.6.17 | ||
=1.8.0 | ||
=1.8.1 | ||
=1.8.2 | ||
=1.8.3 | ||
=1.8.4 | ||
=1.8.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8973 is classified as a medium severity vulnerability that allows remote attackers to bypass access restrictions.
To mitigate CVE-2015-8973, upgrade to MyBB version 1.6.18 or later for 1.6.x and to 1.8.6 or later for 1.8.x.
CVE-2015-8973 affects MyBB versions prior to 1.6.18 and 1.8.x before 1.8.6.
Yes, CVE-2015-8973 also affects the MyBB Merge System versions prior to 1.8.6.
CVE-2015-8973 enables remote attackers to bypass intended access restrictions related to the forum password.