← Zurück zur CVE-Suche

CVE-2026-45128

MyBB

Beschreibung

MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers to change a victim administrator-s default user list view by embedding a specially crafted URL. The Set as Default control named set_default in Admin CP, Users & Groups, Users, View Manager changes the administrator-s default view on GET requests without request forgery protection. The uniquely identifying implementation details include Users & Groups → Users → View Manager, and admin/inc/functions_view_manager.php. This issue is fixed in version 1.8.40.

CVSS 3.5EPSS 0.132%Risiko 0.35
Quelle öffnen
Veröffentlicht
2026-08-18 16:17:08
Betroffene Versionen
<1.8.40
Typ
Webanwendung
Zuletzt geändert
2026-08-18 18:17:37
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N