Skip to content

Usergroups SQL injection

Moderate
dvz published GHSA-3p9w-2q65-r6g2 Mar 10, 2021

Package

MyBB

Affected versions

< 1.8.26

Patched versions

1.8.26

Description

Impact

The Additional User Groups ID numbers can be saved without proper validation in the Admin Control Panel. This data may be fetched and used in SQL queries without proper sanitization, resulting in an SQL injection vulnerability.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Patches

MyBB 1.8.26 resolves this issue with the following changes:

References

For more information

Go to mybb.com/security to report possible security concerns or to learn more about security research at MyBB.

Contact

The security team can be reached at security@mybb.com.

Severity

Moderate

CVE ID

CVE-2021-27948

Weaknesses