CVE-2025-29459: SSRF
Published Apr 17, 2025
·Updated
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
Affected Software
2 affected components
MyBB MyBB
MyBB MyBB=1.8.38
Event History
Apr 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29459?
CVE-2025-29459 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2025-29459?
To fix CVE-2025-29459, upgrade your MyBB installation to version 1.8.39 or later.
3
What type of information can be leaked by CVE-2025-29459?
CVE-2025-29459 allows remote attackers to obtain sensitive information through the Mail function.
4
Which versions of MyBB are affected by CVE-2025-29459?
CVE-2025-29459 affects MyBB versions up to and including 1.8.38.
5
Is there any evidence of exploitation for CVE-2025-29459?
As of now, there have been no widespread reports of active exploitation for CVE-2025-29459.