Impact
The vulnerability lies in the ACP Users View Manager module of MyBB, which accepts GET requests to change an administrator’s default user list view without protecting against cross‑site request forgery. An attacker who can force a victim administrator to load a crafted URL could silently alter the perceived default view for that administrator’s sessions, potentially concealing malicious posts or obfuscating user activity. This represents an unauthorized configuration modification that could affect the integrity of administrative views, but it does not provide direct access to data, code execution, or system privileges.
Affected Systems
MyBB forum software, specifically versions prior to 1.8.40. The flaw exists in the Admin CP under Users & Groups → Users → View Manager and the admin/inc/functions_view_manager.php file. The issue was addressed in MyBB release 1.8.40 and later, made available in the 1.8.40 release package and security advisory.
Risk and Exploitability
The CVSS score is 3.5, indicating low overall severity. EPSS is not available and the vulnerability is not listed in CISA’s KEV catalog, implying limited public exploitation data. The attack requires the victim administrator to be online and load a maliciously crafted URL; the attacker must be on the same site or be able to embed the URL within the administrator’s session. Given these constraints and the low CVSS, the risk is considered low to moderate, but the impact on the administrative configuration may still warrant remediation.
OpenCVE Enrichment