CVE-2025-29458: SSRF
Published Apr 17, 2025
·Updated
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
Affected Software
2 affected components
MyBB Group MyBB
MyBB MyBB=1.8.38
Event History
Apr 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29458?
CVE-2025-29458 is classified as a medium severity vulnerability.
2
How can I mitigate CVE-2025-29458?
To mitigate CVE-2025-29458, you should upgrade to MyBB version 1.8.39 or later.
3
What does CVE-2025-29458 affect?
CVE-2025-29458 affects the Change Avatar function in MyBB versions prior to 1.8.39.
4
Who is at risk from CVE-2025-29458?
Remote attackers can exploit CVE-2025-29458 to obtain sensitive information from vulnerable MyBB installations.
5
Is CVE-2025-29458 present in earlier versions of MyBB?
Yes, CVE-2025-29458 is present in MyBB version 1.8.38 and earlier.