An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. | An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation. |
References |
|
Fri, 18 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-918 | |
Metrics |
cvssV3_1
|
Thu, 17 Apr 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-04-17T00:00:00.000Z
Updated: 2025-04-23T13:02:24.406Z
Reserved: 2025-03-11T00:00:00.000Z
Link: CVE-2025-29459

Updated: 2025-04-18T14:04:11.041Z

Status : Undergoing Analysis
Published: 2025-04-17T22:15:15.387
Modified: 2025-04-23T13:15:57.230
Link: CVE-2025-29459

No data.