MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. In order to exploit the vulnerability, the installer must be unlocked (no `install/lock` file present) and the upgrade script must be accessible (by re-installing the forum via access to `install/index.php`; when the forum has not yet been installed; or the attacker is authenticated as a forum administrator). MyBB 1.8.39 resolves this issue.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Jul 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mybb
Mybb mybb |
|
CPEs | cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:* | |
Vendors & Products |
Mybb
Mybb mybb |
Mon, 02 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 02 Jun 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | MyBB is free and open source forum software. Prior to version 1.8.39, the upgrade component does not validate user input properly, which allows attackers to perform local file inclusion (LFI) via a specially crafted parameter value. In order to exploit the vulnerability, the installer must be unlocked (no `install/lock` file present) and the upgrade script must be accessible (by re-installing the forum via access to `install/index.php`; when the forum has not yet been installed; or the attacker is authenticated as a forum administrator). MyBB 1.8.39 resolves this issue. | |
Title | MyBB's upgrade component vulnerable to local file inclusion | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-02T15:52:36.740Z
Updated: 2025-06-02T16:06:00.967Z
Reserved: 2025-05-28T18:49:07.580Z
Link: CVE-2025-48940

Updated: 2025-06-02T16:05:54.582Z

Status : Analyzed
Published: 2025-06-02T16:15:30.063
Modified: 2025-07-02T15:18:47.520
Link: CVE-2025-48940

No data.