CVE-2017-16780: CSRF
Published Nov 10, 2017
·Updated
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration file.
Affected Software
1 affected component
Mybb Mybb<=1.8.12
Event History
Nov 10, 2017
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is CVE-2017-16780?
CVE-2017-16780 is a vulnerability in the installer of MyBB before version 1.8.13 that allows remote attackers to execute arbitrary code by writing to the configuration file.
2
How severe is CVE-2017-16780?
CVE-2017-16780 has a severity rating of 9.8, which is considered critical.
3
How can I fix CVE-2017-16780?
To fix CVE-2017-16780, you should update MyBB to version 1.8.13 or later.
4
Where can I find more information about CVE-2017-16780?
You can find more information about CVE-2017-16780 on the MyBB blog at [link1] and on Exploit Database at [link2].
5
What is CWE-352?
CWE-352 is a Common Weakness Enumeration category that refers to cross-site scripting (XSS) vulnerabilities.