CVE-2021-3337

HIGH

Hide Thread Content - Incorrect Authorization

Title source: rule

Description

The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading restrictions by clicking on reply or quote in the postbit.

Exploits (1)

exploitdb WRITEUP
by 0xB9 · textwebappsphp
https://www.exploit-db.com/exploits/49496

Scores

CVSS v3 7.5
EPSS 0.1737
EPSS Percentile 95.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-863
Status published
Products (1)
hide_thread_content_project/hide_thread_content 1.0
Published Jan 28, 2021
Tracked Since Feb 18, 2026