BIT-mybb-2022-39265

    Dashboard / Vulnerabilities / BIT-mybb-2022-39265

    BIT-mybb-2022-39265

    Published: 6 Mar 2024Last Modified: 14 Oct 2025

    Summary:

    Details: MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mail_parameters setting value, in connection with the configured mail program's options and behavior, may allow access to sensitive information and Remote Code Execution (RCE). The vulnerable module requires Admin CP access with the `_Can manage settings?_` permission and may depend on configured file permissions. MyBB 1.8.31 resolves this issue with the commit `0cd318136a`. Users are advised to upgrade. There are no known workarounds for this vulnerability.

    Affected packages

    Package

    Name: mybb

    Purl: pkg:bitnami/mybb

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.8.31

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    BIT-mybb-2022-39265 | CVE-DB