SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-4449

Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal…

MEDIUM 6.5EPSS 2.70%

Does this matter?

Lower severity and a low EPSS score (2.70%). Track it; it rarely justifies an emergency change on its own.

Description

Directory traversal vulnerability in MyBB (aka MyBulletinBoard) 1.4.10, and possibly earlier versions, when changing the user avatar from the gallery, allows remote authenticated users to determine the existence of files via directory traversal sequences in the avatar and possibly the gallery parameters, related to (1) admin/modules/user/users.php and (2) usercp.php.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
2.70% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
mybb/mybb
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.