ZeroHour

CVE-2022-43709

CVSS 3.1
4.9 medium
EPSS
<1%p50
Published
()
Modified
Description

MyBB 1.8.31 has a SQL injection vulnerability in the Admin CP's Users module allows remote authenticated users to modify the query string via direct user input or stored search filter settings.

Vendors
mybb
Products
mybb
Weakness
CWE-89, CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.