VulnerabilityModified
CVE-2016-9416
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CRITICAL 9.8EPSS 2.12%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SQL injection vulnerability in the users data handler in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.12% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- mybb/merge system · mybb/mybb
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2016/11/10/8Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/18/1Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/94396Third Party Advisory, VDB Entry
- https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/Patch, Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/11/10/8Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/18/1Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/94396Third Party Advisory, VDB Entry
- https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/Patch, Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.