Vulnerabilities > CVE-2021-3337 - Incorrect Authorization vulnerability in Hide Thread Content Project Hide Thread Content 1.0

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
hide-thread-content-project
CWE-863

Summary

The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

Vulnerable Configurations

Part Description Count
Application
Hide_Thread_Content_Project
1

Common Weakness Enumeration (CWE)