CVE-2016-9420
CRITICALMybb Merge System < 1.8.7 - Improper Input Validation
Title source: ruleDescription
MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors related to "loose comparison false positives."
References (4)
Scores
CVSS v3
9.8
EPSS
0.0111
EPSS Percentile
77.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-20
Status
draft
Affected Products (2)
mybb/merge_system
< 1.8.7
mybb/mybb
< 1.8.7
Timeline
Published
Jan 31, 2017
Tracked Since
Feb 18, 2026