Skip to content

Backups directory .htaccess deletion

Low
dvz published GHSA-94xr-g4ww-j47r Apr 30, 2024

Package

MyBB

Affected versions

< 1.8.38

Patched versions

1.8.38

Description

Impact

The backup management module of the Admin CP may accept .htaccess as the name of the backup file to be deleted, which may expose the stored backup files over HTTP on Apache servers.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L

Patches

MyBB 1.8.38 resolves this issue with the following changes:

References

For more information

Go to mybb.com/security to report possible security concerns or to learn more about security research at MyBB.

Contact

The security team can be reached at security@mybb.com.

Severity

Low

CVE ID

CVE-2024-23335

Weaknesses