MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MyBB 1.8.32 contains a chained vulnerability that allows authenticated administrators to bypass avatar upload restrictions and execute arbitrary code. Attackers can modify upload path settings, upload a malicious PHP-embedded image file, and execute commands through the language configuration editing interface. | |
| Title | MyBB 1.8.32 Authenticated Remote Code Execution via Chained Vulnerabilities | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-22T22:04:08.541Z
Reserved: 2025-12-20T16:31:20.899Z
Link: CVE-2023-53979
Updated: 2025-12-22T21:57:33.395Z
Status : Received
Published: 2025-12-22T22:16:03.540
Modified: 2025-12-22T22:16:03.540
Link: CVE-2023-53979
No data.
OpenCVE Enrichment
No data.