CVE-2025-29459
CVSS 3.1 Score 7.6 of 10 (high)
Details
Summary
CVE-2025-29459 is a vulnerability affecting MyBB version 1.8.38. It enables a remote attacker to extract sensitive information through the Mail function. The specifics of the exploit involve manipulating the function's parameters, potentially leading to information disclosure. However, it's important to note that the vulnerability's validity is disputed by the supplier. They argue that designated Board administrators possess sufficient permissions and that the SSRF (Server-Side Request Forgery) mitigation is in place to prevent such attacks. Yet, until a definitive resolution is reached, it is crucial for MyBB users running version 1.8.38 to apply the available patch or upgrade to a more secure version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- MyBB
Affected Vendors
- myBB