← Πίσω στην αναζήτηση CVE

CVE-2026-45124

MyBB

Περιγραφή

MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark Selected as Read handler is reachable with canmodcp even without canmanagereportedcontent or canmanagereportedposts. When no forums are in scope, $flist_reports is empty and the UPDATE mybb_reportedcontent query executes without the expected permission-based limitation. This issue is fixed in version 1.8.40.

CVSS 4.3EPSS 0.246%Κίνδυνος 0.44
Προβολή πηγής
Δημοσίευση
2026-08-18 16:17:07
Επηρεαζόμενες εκδόσεις
<1.8.40
Τύπος
Εφαρμογή ιστού
Τελευταία τροποποίηση
2026-08-19 15:17:03
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N