CVE-2023-53979
HIGHMyBB 1.8.32 - Authenticated RCE
Title source: llmDescription
MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface.
Exploits (1)
References (5)
Scores
CVSS v3
8.8
EPSS
0.0011
EPSS Percentile
29.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-22
Status
published
Affected Products (1)
mybb/mybb
Timeline
Published
Dec 22, 2025
Tracked Since
Feb 18, 2026