Vulnerabilities > CVE-2017-7566 - Server-Side Request Forgery (SSRF) vulnerability in Mybb

047910
CVSS 7.7 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
mybb
CWE-918

Summary

MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.

Common Weakness Enumeration (CWE)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/142051/SA-20170407-0.txt
idPACKETSTORM:142051
last seen2017-04-10
published2017-04-07
reporterFikri Fadzil
sourcehttps://packetstormsecurity.com/files/142051/MyBB-1.8.10-Server-Side-Request-Forgery.html
titleMyBB 1.8.10 Server-Side Request Forgery