8.3

CVE-2015-8973

xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mybb ≫ Merge System Version <= 1.8.5
Mybb ≫ Mybb Version <= 1.6.17
Mybb ≫ Mybb Version 1.8.0
Mybb ≫ Mybb Version 1.8.1
Mybb ≫ Mybb Version 1.8.2
Mybb ≫ Mybb Version 1.8.3
Mybb ≫ Mybb Version 1.8.4
Mybb ≫ Mybb Version 1.8.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.63% 0.731
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.3 3.9 3.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

http://www.openwall.com/lists/oss-security/2016/11/10/8
Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/11/18/1
Third Party Advisory
Mailing List
http://www.securityfocus.com/bid/94397
Third Party Advisory
VDB Entry
https://blog.mybb.com/2015/09/07/mybb-1-8-6-1-6-18-merge-system-1-8-6-release/
Vendor Advisory
Release Notes