Impact
The Additional User Groups ID numbers can be saved without proper validation in the Admin Control Panel. This data may be fetched and used in SQL queries without proper sanitization, resulting in an SQL injection vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Patches
MyBB 1.8.26 resolves this issue with the following changes:
References
For more information
Go to mybb.com/security to report possible security concerns or to learn more about security research at MyBB.
Contact
The security team can be reached at security@mybb.com.
Impact
The Additional User Groups ID numbers can be saved without proper validation in the Admin Control Panel. This data may be fetched and used in SQL queries without proper sanitization, resulting in an SQL injection vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Patches
MyBB 1.8.26 resolves this issue with the following changes:
.patch
: https://github.com/mybb/mybb/commit/902e5597c4719cbc61443128d980ff4aece2d7a1.patchReferences
For more information
Go to mybb.com/security to report possible security concerns or to learn more about security research at MyBB.
Contact
The security team can be reached at security@mybb.com.