Impact
MyBB forum software allows a user with moderation permissions on a source calendar to move events to any other calendar without checking the target calendar’s moderation rights, creating an unauthorized privilege escalation within the application. This flaw permits the attacker to relocate events that they are not authorized to modify, potentially hiding or exposing sensitive information through calendar entry manipulation. The weakness is a missing authorization check (CWE-863).
Affected Systems
MyBB forum software, versions earlier than 1.8.40. The issue is fixed in version 1.8.40 and later releases.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk level. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated attacker who already has moderation rights on one calendar. Exploitation requires only the ability to trigger the do_move action with appropriate parameters; no additional privileges or external conditions are needed, making the vulnerability relatively easy to exploit on systems where unpatched MyBB is installed.
OpenCVE Enrichment