CVE-2021-27890: SQL Injection
Published Mar 15, 2021
·Updated
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
Affected Software
1 affected component
Mybb Mybb<1.8.26
Remediation
Event History
Mar 15, 2021
CVE Published
via MITRE·05:04 PM
Data Sourced
via MITRE·05:04 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this SQL Injection vulnerability in MyBB?
The vulnerability ID is CVE-2021-27890.
2
What is the severity of CVE-2021-27890?
The severity of CVE-2021-27890 is high with a CVSS score of 8.8.
3
How does the SQL Injection vulnerability in MyBB before 1.8.26 occur?
The SQL Injection vulnerability in MyBB before 1.8.26 occurs via theme properties included in theme XML files.
4
Which versions of MyBB are affected by this vulnerability?
MyBB versions before 1.8.26 are affected by this vulnerability.
5
How can I fix the SQL Injection vulnerability in MyBB?
To fix the SQL Injection vulnerability in MyBB, upgrade to version 1.8.26 or later.