MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. In order to exploit the vulnerability, the installer must be unlocked (no `install/lock` file present) and the upgrade script must be accessible (by re-installing the forum via access to `install/index.php`; when the forum has not yet been installed; or the attacker is authenticated as a forum administrator). MyBB 1.8.39 resolves this issue.
History

Wed, 02 Jul 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Mybb
Mybb mybb
CPEs cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*
Vendors & Products Mybb
Mybb mybb

Mon, 02 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
Description MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. In order to exploit the vulnerability, the installer must be unlocked (no `install/lock` file present) and the upgrade script must be accessible (by re-installing the forum via access to `install/index.php`; when the forum has not yet been installed; or the attacker is authenticated as a forum administrator). MyBB 1.8.39 resolves this issue.
Title MyBB's upgrade component vulnerable to local file inclusion
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-02T15:52:36.740Z

Updated: 2025-06-02T16:06:00.967Z

Reserved: 2025-05-28T18:49:07.580Z

Link: CVE-2025-48940

cve-icon Vulnrichment

Updated: 2025-06-02T16:05:54.582Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-02T16:15:30.063

Modified: 2025-07-02T15:18:47.520

Link: CVE-2025-48940

cve-icon Redhat

No data.