Impact
The flaw arises from an insufficient permission check in MyBB’s calendar selection paths in calendar.php, allowing an authenticated user to view titles of calendars that should be hidden. This is an information disclosure vulnerability (CWE‑863) that compromises the confidentiality of calendar metadata but does not provide code execution or direct system compromise.
Affected Systems
The issue affects all MyBB installations running any version older than 1.8.40. The affected product is MyBB forum software from the mybb:mybb vendor.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a valid authenticated session; an attacker can simply request the calendar selection URLs to enumerate hidden calendar titles. No public exploit or privilege escalation is known, so the risk is limited to the accidental or intentional disclosure of calendar names.
OpenCVE Enrichment