VulnerabilityModified
CVE-2016-9418
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name.
HIGH 7.5EPSS 2.28%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows might allow remote attackers to obtain sensitive information from ACP backups via vectors involving a short name.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.28% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- mybb/merge system · mybb/mybb
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2016/11/10/8Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/18/1Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/94396Third Party Advisory, VDB Entry
- https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/Patch, Release Notes, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2016/11/10/8Mailing List, Patch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/11/18/1Mailing List, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/94396Third Party Advisory, VDB Entry
- https://blog.mybb.com/2016/10/17/mybb-1-8-8-merge-system-1-8-8-release/Patch, Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.