Vulnerabilities > CVE-2017-7566 - Server-Side Request Forgery (SSRF) vulnerability in Mybb
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/142051/SA-20170407-0.txt |
id | PACKETSTORM:142051 |
last seen | 2017-04-10 |
published | 2017-04-07 |
reporter | Fikri Fadzil |
source | https://packetstormsecurity.com/files/142051/MyBB-1.8.10-Server-Side-Request-Forgery.html |
title | MyBB 1.8.10 Server-Side Request Forgery |
References
- https://blog.mybb.com/2017/04/04/mybb-1-8-11-merge-system-1-8-11-release/
- https://github.com/mybb/mybb/commit/f5de8fc2aad11e0d2583f585535ccfa2b46325db#diff-7fe6e55397c77ab9a0f5d57bc4cbe5b9R6781
- http://www.securityfocus.com/bid/97480
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170407-0_MyBB_SSRF_vulnerability_v10.txt