First published: Thu Apr 17 2025(Updated: )
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MyBB |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29459 has been classified as a medium severity vulnerability.
To fix CVE-2025-29459, upgrade your MyBB installation to version 1.8.39 or later.
CVE-2025-29459 allows remote attackers to obtain sensitive information through the Mail function.
CVE-2025-29459 affects MyBB versions up to and including 1.8.38.
As of now, there have been no widespread reports of active exploitation for CVE-2025-29459.