CVE-2023-41362

HIGH

MyBB <1.8.36 - Code Injection

Title source: llm

Description

MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within PHP.

Exploits (1)

nomisec WORKING POC 7 stars
by SorceryIE · poc
https://github.com/SorceryIE/CVE-2023-41362_MyBB_ACP_RCE

Scores

CVSS v3 7.2
EPSS 0.2354
EPSS Percentile 95.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-94
Status published

Affected Products (1)

mybb/mybb < 1.8.36

Timeline

Published Aug 29, 2023
Tracked Since Feb 18, 2026