Skip to content

ACP Languages local file inclusion

High
dvz published GHSA-cpfv-6f8w-759r Jan 3, 2023

Package

MyBB

Affected versions

< 1.8.33

Patched versions

1.8.33

Description

Impact

Path traversal vulnerability in the Admin CP's Languages module allows remote authenticated users to include and execute arbitrary local files (LFI).

The vulnerable module requires Admin CP access with the Can manage language packs? permission.

Patches

MyBB 1.8.33 resolves this issue with the following changes:

References

For more information

Go to mybb.com/security to report possible security concerns or to learn more about security research at MyBB.

Contact

The security team can be reached at security@mybb.com.

Severity

High
7.2
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
High
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVE ID

CVE-2022-45867

Weaknesses