CVE-2025-29460: SSRF
Published Apr 17, 2025
·Updated
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
Affected Software
2 affected components
MyBB Group MyBB
MyBB MyBB=1.8.38
Event History
Apr 17, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-29460?
CVE-2025-29460 is classified as a high severity vulnerability due to its potential to expose sensitive information.
2
How do I fix CVE-2025-29460?
To fix CVE-2025-29460, you should upgrade to MyBB version 1.8.39 or later, which addresses this vulnerability.
3
What type of information can be exposed by CVE-2025-29460?
CVE-2025-29460 allows remote attackers to potentially access sensitive information such as user data through the Add Mycode function.
4
Which versions of MyBB are affected by CVE-2025-29460?
MyBB versions prior to 1.8.39 are affected by CVE-2025-29460.
5
Can CVE-2025-29460 be exploited remotely?
Yes, CVE-2025-29460 can be exploited remotely by attackers to obtain sensitive information.