CVE-2022-24734

HIGH LAB

MyBB Admin Control Code Injection RCE

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2022-24734. PoCs published by Altelus, Altelus1, lavclash75, including Metasploit module exploits/multi/http/mybb_rce_cve_2022_24734.

AI-analyzed exploit summary This exploit leverages a vulnerability in MyBB's Admin CP to achieve RCE by injecting malicious PHP code into the 'Add New Setting' feature. It requires admin credentials and exploits insufficient input validation in the 'type' parameter.

Description

MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change Settings_ pages. This results in a Remote Code Execution (RCE) vulnerability. The vulnerable module requires Admin CP access with the `Can manage settings?` permission. MyBB's Settings module, which allows administrators to add, edit, and delete non-default settings, stores setting data in an options code string ($options_code; mybb_settings.optionscode database column) that identifies the setting type and its options, separated by a new line character (\n). In MyBB 1.2.0, support for setting type php was added, for which the remaining part of the options code is PHP code executed on Change Settings pages (reserved for plugins and internal use). MyBB 1.8.30 resolves this issue. There are no known workarounds.

Exploits (4)

exploitdb WORKING POC
by Altelus · pythonwebappsphp
https://www.exploit-db.com/exploits/50924

This exploit leverages a vulnerability in MyBB's Admin CP to achieve RCE by injecting malicious PHP code into the 'Add New Setting' feature. It requires admin credentials and exploits insufficient input validation in the 'type' parameter.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MyBB 1.8.29
Auth required
Prerequisites: Admin credentials for MyBB Admin CP · Access to the 'Add New Setting' feature
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 48 stars
by Altelus1 · poc
https://github.com/Altelus1/CVE-2022-24734

This PoC exploits CVE-2022-24734, an RCE vulnerability in MyBB's Admin CP by injecting malicious PHP code into the 'Add New Setting' feature. It leverages command injection via the 'extra' field in the configuration settings.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MyBB 1.8.29
Auth required
Prerequisites: Valid admin credentials · Access to MyBB Admin CP · Permission to add/update settings
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by lavclash75 · poc
https://github.com/lavclash75/mybb-CVE-2022-24734

This is a functional exploit for CVE-2022-24734, targeting MyBB 1.8.29. It leverages an authenticated RCE vulnerability in the Admin CP's 'Add New Setting' feature by injecting malicious PHP code into the 'extra' field of a new setting.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MyBB 1.8.29
Auth required
Prerequisites: Valid admin credentials for MyBB Admin CP · Access to the 'Add New Setting' feature
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Cillian Collins, Altelus, Christophe De La Fuente · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/mybb_rce_cve_2022_24734.rb

This Metasploit module exploits an improper input validation vulnerability in MyBB prior to 1.8.30, allowing authenticated administrators to execute arbitrary code via PHP `eval` function. The exploit adds a malicious setting, injects the payload, and triggers execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MyBB < 1.8.30
Auth required
Prerequisites: Valid MyBB admin credentials · Access to MyBB Admin Control Panel
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/mybb/mybb/security/advisories/GHSA-876v-gwgh-w57f
Release Notes, Vendor Advisory x_refsource_misc
https://mybb.com/versions/1.8.30/
Third Party Advisory, VDB Entry, Vendor Advisory x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-22-503/
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/167082/MyBB-1.8.29-Remote-Code-Execution.html

Scores

CVSS v3 7.2
EPSS 0.7768
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
mybb/mybb 1.2.0 - 1.8.30
Published Mar 09, 2022
Tracked Since Feb 18, 2026