CVE-2016-9403: Critical severity MyBB Merge System vulnerability
Published Jan 31, 2017
·Updated
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.
Affected Software
2 affected components
MyBB Merge System<=1.8.6
MyBB MyBB<=1.8.6
Remediation
Patch Available
Patch Available
Event History
Jan 31, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Data Sourced
via NVD·10:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9403?
CVE-2016-9403 is rated as a medium severity vulnerability due to its potential to allow unauthorized actions without proper permission checks.
2
How do I fix CVE-2016-9403?
To fix CVE-2016-9403, you should upgrade MyBB and MyBB Merge System to version 1.8.7 or later.
3
What impact can CVE-2016-9403 have on my system?
CVE-2016-9403 can lead to unauthorized access and actions by remote attackers due to the missing permission checks in the code.
4
Is CVE-2016-9403 present in newer versions of MyBB?
No, CVE-2016-9403 is only present in MyBB versions earlier than 1.8.7.
5
Which versions of MyBB are affected by CVE-2016-9403?
MyBB versions up to and including 1.8.6 are affected by CVE-2016-9403.