MEDIUM
MyBB (aka MyBulletinBoard) 1.4.3 includes the sensitive my_post_key parameter in URLs to moderation.php with the (1) mergeposts, (2) split, and (3) deleteposts actions, which allows remote attackers to steal the token and bypass the cross-site request forgery (CSRF) protection mechanism to hijack the authentication of moderators by reading the token from the HTTP Referer header
Published Aug 25, 2009
6.8
MEDIUMCVSS 2.0
EPSS 0.60%
Description
Affected products
Remediation
Metrics
References (5)
Change history (0)
No recorded changes yet.