Vulnerabilities > CVE-2017-7566 - Server-Side Request Forgery (SSRF) vulnerability in Mybb
Attack vector
NETWORK Attack complexity
LOW Privileges required
SINGLE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Packetstorm
data source | https://packetstormsecurity.com/files/download/142051/SA-20170407-0.txt |
id | PACKETSTORM:142051 |
last seen | 2017-04-10 |
published | 2017-04-07 |
reporter | Fikri Fadzil |
source | https://packetstormsecurity.com/files/142051/MyBB-1.8.10-Server-Side-Request-Forgery.html |
title | MyBB 1.8.10 Server-Side Request Forgery |
References
- http://www.securityfocus.com/bid/97480
- https://blog.mybb.com/2017/04/04/mybb-1-8-11-merge-system-1-8-11-release/
- https://github.com/mybb/mybb/commit/f5de8fc2aad11e0d2583f585535ccfa2b46325db#diff-7fe6e55397c77ab9a0f5d57bc4cbe5b9R6781
- https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20170407-0_MyBB_SSRF_vulnerability_v10.txt