Description
MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection mechanism to hijack the authentication of moderators by reading the token from the HTTP Referer header.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2008-7041 | MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection mechanism to hijack the authentication of moderators by reading the token from the HTTP Referer header. |
References
History
Fri, 26 Sep 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mybb
Mybb mybb |
|
| CPEs | cpe:2.3:a:mybb:mybb:1.4.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Mybboard
Mybboard mybb |
Mybb
Mybb mybb |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T11:56:14.019Z
Reserved: 2009-08-24T00:00:00.000Z
Link: CVE-2008-7082
No data.
Status : Deferred
Published: 2009-08-25T10:30:00.733
Modified: 2025-09-26T19:39:38.973
Link: CVE-2008-7082
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD