CVE-2016-9403

CRITICAL

MyBB <1.8.7 - Info Disclosure

Title source: llm

Description

newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.

Scores

CVSS v3 9.8
EPSS 0.0533
EPSS Percentile 89.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-264
Status draft

Affected Products (2)

mybb/merge_system < 1.8.6
mybb/mybb < 1.8.6

Timeline

Published Jan 31, 2017
Tracked Since Feb 18, 2026