← back
CVE-2023-53979highCWE-22

MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.6epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
In short

MyBB 1.8.32 allows logged-in administrators to upload malicious files by bypassing upload restrictions and then execute harmful code on the server. This happens because the software doesn't properly validate file uploads and allows editing of settings that control where files are stored.

Technical detail

An authenticated administrator can chain multiple vulnerabilities to achieve RCE: modify upload directory settings via configuration, upload a PHP-embedded image file that bypasses avatar upload validation (CWE-22 path traversal), and execute arbitrary code through the language configuration interface. Requires admin-level privileges but achieves complete code execution on the target system.

Summary generated and translated by AI from the official description.
MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Mybb · MyBB