Impact
MyBB forum software before version 1.8.40 contains an authorization flaw in the calendar module. The code that retrieves events does not consistently enforce the private‑event flag, allowing users who have permission to view or moderate the calendar to see and modify events that are meant to be private. This flaw, identified as CWE‑639, lets an attacker bypass intended restrictions on calendar event visibility and management.
Affected Systems
The vulnerability affects the MyBB forum software package published by the MyBB organization. Any deployment running MyBB version 1.8.39 or older is impacted; version 1.8.40 and later contain the fix.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. No EPSS value is available, and the flaw is not listed in the CISA KEV catalog. The exploit requires authentication to an account that has at least viewing or moderation rights on the calendar, which is typically obtainable through a normal user session. An attacker could therefore read non‑public event data and potentially modify event details, compromising the confidentiality and integrity of private calendar information.
OpenCVE Enrichment